Graylog Sizing / Architecture

Dear all,

we are currently using the Graylog OVA image.
We have about 10.000.000 Logs per day. Our Server runs with 8 vCPU’s, 16 GB RAM and about 300 GB disk space.
The performance is pretty good.

We now have some requirements to increase the daily Logs up to 100.000.000 per day. Do we now have to change our environment to a Multi-Node Setup or what is the recommendation?

If so, how many servers do you recommend?

Thank you!
BR
Steffen

dear @zoscail

it highly depends how long did you want to keep the logs and how much you are searching on them and how much processing you do.

But having Graylog and Elasticsearch not on the same Host should be the first step.

1 Like

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.