Logs not coming when backlog exceeded 1M


(Tafsir) #1

Hi All

Seen a new Issue in graylog.

When backlog exceeded 1M on graylog node then logs stop coming to the stream or in the dashboard. And when it starts decreasing below 1M logs start coming. Not able to understand the issue, Please help me to solve this.

Graylog version - 2.4.6
Elasticsearch Version - 5.6

Thanks


(Jan Doberstein) #2

He @Tafsir_Alam

when you try to tell us that if your journal is over 1 million messages the messages are dropped than you have two things you should do:

  1. increase the Elasticsearch ressources to be able to work with your ingest rate
  2. raise your journal size in the server.conf

(system) #3

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.