Im really new to graylog and very flashed of the good functionality.
Unfortunately I have the same issues regularly. We are collecting logs 200messages/s
Here are the specs: 3 nodes, every has 4 CPUs and 16 GiB RAM.
Diskspace is nearly empty.
It is no option for us to loose the messages. How can I prevent this from happening? And how can I tell graylog, to start processing the disk journal?