we are currently trying to use Graylog as a new syslog server and built a POC with it. But at the moment I have got the problem that after a full disk at the weekend it only processes the messages really really slowly. Like 25 Messages per second.
What I did was to delete all indices files after the server was full and creating a new one. And I also deleted the journal files after stopping the graylog services and restarting it.
Elasticsearch seems be fine and in a green state. I already reinstalled everything but I think some configfiles didn’t get deleted because the problem is still there. Do you have any ideas for this problem? I like graylog very much but at the moment it’s not usable.