To be honest, I’m thinking to stop using the archiving system of Graylog, in favor of the OpenSearch snapshot system, who is 1 million faster, and do the same job.
My understanding is that archiving will be able to run in parallel and achieve linear speed-up based on allocated resources.
Snapshots will be faster; but it’s also not exactly the same thing.