Has anyone successfully managed to put all the data collected by Graylog on a second hard-drive or partition, in order to have the place where the logs are stored and the OS space separated ?
If yes, can you explain how you did ?
Here is my configuration :
Debian 11
Graylog 4.3.7
Elasticsearch (transitionning to OpenSearch in the next few weeks)
The data collection is located in the Elastic DB (default /var/lib/elasticsearch/) and The journal is located at /var/lib/graylog/journal (default). GL-Configurations is here (default /var/lib/mongodb).
You can set that as a separate mount points. Is this what you mean?
Hum yes maybe, what I don’t want is having my 60G drive filled with logs ^^
So playing with fstab may be the solution to get the /var/lib/elasticsearch/ on the 2To drive ?