1. Describe your incident:
Large number of deleted messages in the index stats page.
2. Describe your environment:
- OS Information:
Ubuntu 20.04 - Package Version:
Graylog 4.3.5 - Service logs, configurations, and environment variables:
Clean installation of Ubuntu and Graylog, no other packages installed, logs coming from a Windows machine with Graylog Sidecar and Filebeat… all default settings.
3. What steps have you already taken to try and solve the problem?
I have looked around and there are a couple of posts about this, they say some other process might be deleting from Elasticsearch directly, as this is a clean installation that is unlikely.
4. How can the community help?
On my other Graylog instances I’m not having this issue, and I’m not sure how to verify if there are indeed logs being deleted or not.
If you can provide any guidance on how to investigate this… Thank you.