Process logs in the source

Hello everyone,
Is there anyway to process logs in the source machines in order to reduce the load of Graylog nodes?

Hey @ncmfn,

Can you elaborate on what you mean? Of course it you have a lot of pipeline rules and extractors that will cause CPU utilization by the graylog-server service to increase. You can eliminate those by preprocessing the data so it is received by Graylog already prepared to be indexed. You can also move the elasticsearch and mongo services on dedicated servers to further reduce load on the server hosting the Graylog service. So the answer is yes. If you’ll be more specific we may be able to prescribe particular configurations.

thanks,
you gave me a better idea of how to reduce Graylog load.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.