It seems whenever I restart Graylog all the inputs start by default.
I have a couple of Inputs that I only start as needed because they consume a lot of database/CPU resources. Can I configure an input that does not start by default unless the system administrator explicitly starts it?
I setup a Stream to handle this particular input called ASA_AnyConnect
I setup a Pipeline called “Bit_Butcket” and connected it to the ASA_AnyConnect Stream.
That pipeline has one stage with one rule:
rule "Drop_Message"
when
true
then
drop_message();
end
This plan seems good except for two issues:
It doesn’t work. The stream shows thousands of msg/s but the pipeline shows zero msg/s. Probably user error as this is my first pipeline I’ve setup.
If it did work, it remains to be seen how much this would help me. Without this rule, turning on this input pegs all four of my CPUs and makes the whole system unresponsive. With this rule, would it be any better? It would certainly save on my disk space, but I’m primarily interested in the system staying responsive and performant.
Can someone suggest what I should do to trouble shoot this? What can I post to this message board to help with the troubleshooting?