Couldn’t find any solution to this so here I am asking you guys. Basically, I have a UDP input for all my network devices and it can only process out about 3.5K msg/s. After that, the process buffer starts filling up so it was probably an extractor or some other parsing process causing this. Turns out that if I disable the force rDNS option, the input can process up to 14K msg/s
Question is, how can I improve this? It looks like I have to use rDNS since some syslog messages get erroneous source names if I don’t.