Your process_buffers & output_buffers should match the amount of CPU cores you have on that node, if not you may want to either lower them or add more resource to that node. with that many logs in the journal it might be a while, all depends of what resource you have commited to this node. I would also check the log file on both Graylog and elasticsearch. If you have bad extractors and/or pipelines this could also be part of the issue.