Hi Manel, check if your Elasticsearch cluster is fast enough to ingest the messages at the same rate Graylog is receiving them and check the utilization of your input/process/output buffers on the System / Nodes / Node details page.
Cheers, Jochen On Tuesday, 4 October 2016 09:49:17 UTC+2, Manel wrote: > > Hi, > > I am using a cluster of 2 graylog server. Now that i am receiving > 80klogs/s i have some problem with graylog; "Journal utilization is too > high" et " Uncommited messages deleted from journal" the web interface is > a little bit slow also. So i was wounderind if this maybe an elasticsearch > problem if my elastic cluster can't hundle logs fast enough or is it a > graylog capacity problem. > > I have 3 elasticsearch machines with 4 primary shard and no replica > > Thanks > -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/graylog2/b3e01bc5-6ec4-4ed4-9169-23fc21b68bf6%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
