We are facing an issue with Logstash parsing, Initially parsing speed is very high and then it decreases gradually, because of this we have around 10 gb of data in queue. We tried increasing swap size, increasing workers and restarted Logstash nodes but not working as expected. Below are the environment details
Elastic cluster: 3 master + data Nodes
Logstash: 4 Nodes
CPU : 8 CPU
Ram: 2 servers with 16gb and other servers: 32 gb