We have cluster of four Graylog instances in our infrastructure.
We mostly use Kafka as our input source.
We encountered several cases from time to time, where the input rate is very high - can reach 200k per sec. Output rate cannot reach such a rate, and this situation causes the journal to fill up pretty quickly and the processing buffer to get full, until the input rate goes back down so the output can catch up.
I wanted to ask about the setting: “Allow Throttling This Input” - If enabling it, when should I expect it to become effective? How does it affect the infrastructure ?
I tried to use it when we gained the high input rate, but nothing changed regarding the rates or the behaviour of the input.