Something I’m keen to understand is the difference between outgoing traffic and the size of messages in Elasticsearch.
I’ve been trying out adding a new service to Graylog and this has significantly increased the outgoing traffic.
When I export all the log messages that this new service has pushed to Graylog, the total message size is in the region of 80 MB. However, this appears to correlate to approximately 20 GB of additional outgoing traffic over the same period.
We also calculated the message size for ALL messages over a given period. The message size was 3 GB, but total outgoing traffic for the same period was around 14 GB.
- There is only one Index Set configured and all streams are set to use this
On investigation, I came across this post:
Which contains the cryptic line " be warned, that the size of the messages in Elasticsearch is not equal to the outgoing traffic in Graylog (on the System page)."
- Any thoughts on what might explain the discrepancy we are seeing?
- Can anyone elaborate on the difference between message size and outgoing traffic?