I have had a look around but have not been able to find an answer on this one.
We have just deployed a new Graylog setup (Currently only 1 Graylog server and 1 separate Elasticsearch server) and I would like to know what I should be expecting with the In vs Out messages.
I would expect that they would be roughly the same, however at the moment our incoming number is a lot higher then the outgoing (currently 247in/82 out). I have also seen the Out significantly higher.
So I guess my questions are:
Should the In/Out number of messages be relatively even?
What does a much higher In than Out indicate?
What does a much higher Out than In indicate (slow writing to Elasticsearch?)
Thanks guys. We are now pretty constantly seeing about double the out vs in (247/547). The disk journal utilization is at 1%, Input,Output and Process buffers are sitting at 0%.
Thanks Jan. Actually I somewhat figured this out this afternoon but forgot to update this thread. It clicked in my mind that the only non standard thing we were using was the netflow plugin. I disabled this input and then sure enough the in/out was 50/50.
So I am not sure now if the plugin or netflow itself is the issue. But at least I am narrowing it down and have stopped the double up for now.