# Journal utilization is too high - process buffer 100%

**URL:** <https://community.graylog.org/t/journal-utilization-is-too-high-process-buffer-100/23005>\
**Category:** Graylog Central (peer support)\
**Tags:** alert, elastic\
**Created:** [March 11, 2022, 4:27pm UTC](https://community.graylog.org/t/journal-utilization-is-too-high-process-buffer-100/23005 "2022-03-11T16:27:01Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [March 12, 2022, 1:16am UTC](https://community.graylog.org/t/journal-utilization-is-too-high-process-buffer-100/23005/2 "2022-03-12T01:16:17Z")

</div>

Hello @Chase

I see there has been some issues in the past with the journal.

- [Graylog high journaling and low output rate](https://community.graylog.org/t/graylog-high-journaling-and-low-output-rate/21886)

Ill try to explain those messages above.

> [@Chase](#):
>
> Nodes with too long GC pauses (triggered 18 hours ago)  
> There are Graylog nodes on which the garbage collector runs too long. Garbage collection runs should be as short as possible. Please check whether those nodes are healthy. (Node: _602a0297-afdf-49ce-83aa-7b5b141aee1d_ , GC duration: _1379 ms_ , GC threshold: _1000 ms_ )

You may find that answer here for that log message.

- [Garbage collection runs](https://community.graylog.org/t/garbage-collection-runs/22868)

> [@Chase](#):
>
> Journal utilization is too high (triggered 15 hours ago)  
> Journal utilization is too high and may go over the limit soon. Please verify that your Elasticsearch cluster is healthy and fast enough. You may also want to review your Graylog journal settings and set a higher limit. (Node: _602a0297-afdf-49ce-83aa-7b5b141aee1d_ )

Seams like you having issues with Elasticsearch, I would check you status/health of your Elasticsearch.

`curl -XGET http://localhost:9200/_cluster/health?pretty=true`

Knowing what your Graylog and elasticsearch configurations look like, I might be able to help further.

> [@Chase](#):
>
> 1. Uncommited messages deleted from journal (triggered 15 hours ago)  
> Some messages were deleted from the Graylog journal before they could be written to Elasticsearch. Please verify that your Elasticsearch cluster is healthy and fast enough. You may also want to review your Graylog journal settings and set a higher limit. (Node: _602a0297-afdf-49ce-83aa-7b5b141aee1d_ )

When your journal get to full this will happen, hence something is wrong with Elasticsearch. Since Elasticsearch grabs the messages from the journal and indices them. that would be the first place I would look, especially the logs. You maybe having a problem all this time but it takes a few days to notice. No need to reboot all your doing is restarting the services and perhaps cleaning out the journal.  
To be honest I would go over all you logs ` /var/log` to find if anything could pertain to this issue. If you running a load balancer ( i.e. nginx/apache) I would also check those logs.  
What version are you running?

- Elasticsearch
- Graylog
- MongoDb

This also could be a direct results with resources and distributions of resources.  
It possible Graylog HDD is getting full and Elasticsearch stops index message in the journal, hence filling up until you reboot.

`root # df -h`

If you can try restarting Graylog service and tail its log file

`systemctl restart graylog-server`

and

`tail -f /avr/log/graylog/server.log`

Watch how Graylog starts up and check for issues, just a thought you may find something.

---

_[View the full topic](https://community.graylog.org/t/journal-utilization-is-too-high-process-buffer-100/23005)._
