I'm using rsyslog-elasticsearch to writing nginx accesslog into Elasticsearch cluster. I found the document told that the plugin would use queue.dequeuesize as the bulk size.But my tcpdump show that every POST only has 8-9 events in the bulk body while my input flow is nearly 10k per second.
How can I force a larger bulk size? _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.

