I’ve searched through the documentation pages as well as here in the forum, but couldn’t find any indication on how many active shards are recommended.
From what I understand though, the higher the number of active shards the more resources are allocated (slowish performance of search queries?!).
Currently I only have 1 graylog server (1 node) and 1 elasticsearch server… the following settings are configured in my graylog server.conf
elasticsearch_max_docs_per_index = 20000000 elasticsearch_max_number_of_indices = 20 retention_strategy = delete elasticsearch_shards = 4 elasticsearch_replicas = 0
However, graylog say I have currently 24 active shards. My index says I have 6 indices with a total of 1,107,432,833 messages under management, current write-active index is graylog_5.
So far I’ve been using the pre-configured settings in the server.conf … is it recommended or am I going to run into a bottleneck in terms of performance and cluster-health any time soon?
what do you think?
happy to provide more information