Hi Jan, your are right, my question is really ambiguous, sorry for that. I’m brand new on Graylog and i’m not a sysadmin, I read forums and some documentation to try to solve this thing. Sometimes work fine, but sometime not.
Here are some data:
Errors:
And:
CPU:

Memory and Buffer
Elasticsearch data

Services running:

Inputs running:
Disk:

Things than I try:
- When i delete all indices, the shards gone, but later i get shards again.
- I send very less message to the 3th input (changing logging level), and get better
So, i think someone change the configuration of one device, modifying the logging level, so graylog exploted. I don’t know if this the definitive solution, but i’ll see it in these days.
Thanks the reply, and the pacience ;).
Have a good friday, and sorry my English
Monchito