I’m having performance issues on our Graylog installation. It can’t keep up with incomming messages, and I need some tips on improving.
The version is 2.4.6, on docker on Ubuntu. I have a standard 1 node setup with Graylog, ES and Mongodb on seperate docker containers.
The processing shows 100 utilization, and memony consumption jumps up 3 times from up from around 1gb to 1.6 gb of 1.8 in steps each second and then return to 1gb.
Process buffer is full/100%
I have a processing average on 500-1000 msg per second.
The docker PS shows and CPU utilization on 90-140%.
I guess I’ll might have to bring in more CPU power, or maybe tweak the number of processor buffers?
I only have a single rule and a pipeline setup. All really simple and it seems to be very restricted in what it is doing.
AWS lookup and GeoIP resoler are disabled.
Any hints to what I can do for getting better performance?
Best regards, Peter Meldgaard