I have a Graylog server with 500GBs of disk space. I have just 1 index set where all messages go to. I need to keep logs for the last 5 months, they can be deleted after those 5 months. I had issues before as the disk got filled up completely and Graylog stopped working. Don’t want that to happen again so I am looking at message retention for indices, but I am still not sure how to configure it.
This is my current configuration (I did not configure this, the server was handed overt to me and I am trying to set it up properly):
(it says 49 years ago but obviously that is not true, the graylog server was built less than a year ago)
How can I achieve my goal (keeping just the last 5 months of logs) so the disk does not get filled up again?
What is the best way of doing what I need without loosing any of the current logs that are newer than 5 months?