We have a cluster with 2 Graylog and 4 Elastic Nodes. During index optimization, the number of unprocessed messages increases dramatically and the elastic nodes seem to slow indexing messages too much. Does anyone know a solution for this issue or have experience with customizing the index.merge.scheduler.throttle value in Elastic?
you might want to lower the refresh.index setting in your index template to something around 30seconds. This would be one option to lower the pain on elasticsearch.