Hello community;

My situation is that graylog would stop processing messages everyday at the 
same time around midnight.

Setup:

   - Single node running the entire graylog stack
   - 2x Intel(R) Xeon(R) E5440 2.83GHz, 16GB RAM
   - Graylog Heap Space 2GB
   - Elasticsearch Heap space 4GB


Symptoms:

10 minutes after midnight, I notice the following.

   - In xxx / Out 0 msgs/s
   - Process buffer grows to 100%
   - Journal keeps growing in size
   - Input buffer and Output buffer are both at 0%
   - Utilization keeps growing, number of unprocessed messages increasing, 
   xxx messages have been appended in the last second, 0 messages have been 
   read in the last second.

You can download the log from here 
<https://transfer.sh/gwmJQ/server.log.tar.gz>, this is covering the 
affected period, some highlights from the log:
2016-10-09T00:08:06.939+02:00 DEBUG [StreamMatcherFilter] Routed message 
<b0f4aeb1-8da3-11e6-9e21-002219562f79> to 0 streams. <= Last routed message
2016-10-09T01:30:01.339+02:00 INFO  [Server] SIGNAL received. Shutting 
down. <== Restarted graylog-server

Once I restart graylog-server, empty the journal manualy and recycle 
defelctor, graylog comes back to life.

Any ideas on what is causing this?

P.S: IPs in log has been masked to protect the innocent.

Best Regards

-- 
You received this message because you are subscribed to the Google Groups 
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/graylog2/c187c7b1-3b7f-4270-95bc-0dd93096ddcc%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to