I have used a shell to open a long TCP connection for send messages to a Graylog server in a test bed.
my problem is the output (to Elasticsearch) message rate(1.5K to 2K MPS) are not matched input message rate(12K to 13K MPS). My Elasticsearch cluster with 3 servers all are KVM virtual host, each with 2 cores and 24 GB RAM.
i am observing the improvements by adjust the resources to ES KVM hosts. but i want to know if your guys have any suggestion on this.