We recently installed Graylog and I cannot for the life of me get the logs into elasticsearch quick enough so our unprocessed message count keeps increasing.
We have a CentOS7 server. 8x CPU. 64GB Memory. 20GB assigned to the Graylog Heap. 20GB assigned to the elasticsearch heap.
My server.conf file had these settings
processbuffer_processors = 5
outputbuffer_processors = 3
inputbuffer_processors = 2
I found another post which indicated to tinker with these but changing the values (and restarting the service) hasn’t helped.
I’m quite new to Graylog so any support would be great (and please dumb stuff down for me as much as you can to get me back onto the right track).
Thanks in advance