1. Describe your incident:
GrayLog is ingesting more than 10GB of data everyday from our 10-12 windows servers event log. We would like to understand why is the volume of ingestion so high?
2. Describe your environment:
-
OS Information: Ubuntu 18.04.5 LTS
-
Package Version: 4.0.15+a7bed0d, codename Noir
-
Service logs, configurations, and environment variables:
3. What steps have you already taken to try and solve the problem?
Changed the daily ingestion interval on sidecar.yml to 24 hours from the intial 10 seconds but our daily data usage shown on the GrayLog system overview is around 10GB
4. How can the community help?
Can someone please explain to me how GrayLog system overview calculates the volume of data ingested from my Windows event logs using sidecars? I want to visualise how much event log is getting pushed through by each server and if the update interval on sidecar.yml has impact on this volume?
#GrayLog #sidecar #communityeditioin