the main problem is - elasticsearch is not a metric storage.
I can understand from one point that you do not want to add another piece of software to your stack - but it is like going on the race track with a jeep. Yes it is working but the fun starts in a racing car …
I have settled on a Prometheus and Grafana setup for monitoring Graylog. I am using the prometheus Graylog plugin. It seems to work well and we have some nice dashboards in Grafana.