The full process and output buffer usually means it can’t write out the message to Elasticsearch.
So maybe your graylog servers “need” only 400% CPU and your elastic have a bottleneck.
So I suggest to check the elasticsearch cluster first. CPU, and disk IO.
But a wrong config can also cause simmilar error, please upload your config as @jochen asked.