On productive stand have 2 VM (4cpu, 12gb ram in each).
Graylog+elasticsearch+mongodb on each node and all in the docker.
All settings are set to default except:
ES_JAVA_OPTS: -Xms4g -Xmx4g (for elasticsearch)
GRAYLOG_OUTPUT_BATCH_SIZE: 1000 and GRAYLOG_OUTPUTBUFFER_PROCESSORS: 4 (for graylog).
NTP is correctly working on all nodes.
Elasticsearch cluster health is green.
Pipeline and extractors is not set.
In graylog have problem with too many uncommited messages:
In peak I have about 5000 messages per second.
What else can i do besides increasing resources?
ps sorry for my english - using gtranslate