we are currently trying to use Graylog as a new syslog server and built a POC with it. But at the moment I have got the problem that after a full disk at the weekend it only processes the messages really really slowly. Like 25 Messages per second.
What I did was to delete all indices files after the server was full and creating a new one. And I also deleted the journal files after stopping the graylog services and restarting it.
Elasticsearch seems be fine and in a green state. I already reinstalled everything but I think some configfiles didn’t get deleted because the problem is still there. Do you have any ideas for this problem? I like graylog very much but at the moment it’s not usable.
the elasticsearch log only shows informational messages and no problems: https://pastebin.com/Uuzx9CDk
I checked the possible output but there is nothing configured. So I tried to forward the default output but there don’t appear any messages at the other syslog server.
In the default stream I still see the new messages that get processed but really slow.
Here are some pictures maybe its possible to see the problem here…