I had a storage issue on my virtual host where the host itself ran out of disk space.
After clearing the issues up and reclaiming the storage I rebooted both the Graylog Node and the Elasticsearch node (separate VMs).
Now in GL the journal has 1.4million messages queued and GL isn’t processing them. I assume the journal became corrupted (though I can’t see anything in the logs).
Looking through the forum at similar issues is the only solution to delete the journal directory on the GL server and therefore lose all the journaled messages?