Last week I had two index failures due to too long stack traces.
The Graylog server had stopped responding and I had to restart it.
The debugging of such index failures is a pain in the a… But that’s another point.
How do you prevent your environment from such faults ? I tried it with a custom mapping and ignore_above, but the message field is a text field (because of field anaylsis ) and ignore_above works only with a keyword.