I have had a look around but have not been able to find an answer on this one.
We have just deployed a new Graylog setup (Currently only 1 Graylog server and 1 separate Elasticsearch server) and I would like to know what I should be expecting with the In vs Out messages.
I would expect that they would be roughly the same, however at the moment our incoming number is a lot higher then the outgoing (currently 247in/82 out). I have also seen the Out significantly higher.
So I guess my questions are:
- Should the In/Out number of messages be relatively even?
- What does a much higher In than Out indicate?
- What does a much higher Out than In indicate (slow writing to Elasticsearch?)