Sometimes can see significant drop in logs

(Tafsir) #1

Hi All,

From few days I noticed significant drop in the logs. Can see gap in the logs. Nothing unusual found in the logs. Please help me in this.

Graylog version - 2.4.6
Elasticsearch version - 5.6

Thanks in advance

(Jan Doberstein) #2

This could be:

  • The source not sending data
    • the collector having issues
  • something in your network
    • network saturation
    • switch reboot
  • something in Graylog
    • reboot
    • high load
  • something in Elasticsearch
  • reboot
  • high load

As you see the list is not short and the investigation is something that you can do from the inside only.

(Tafsir) #3

Thanks @jan For the useful info.

(system) #4

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.