I am sending data from filebeat (6.3) from 138 servers to elastic search 6.3.( 3 master and 17 data nodes with (6data node 30gb memory and 11 with 15gb memeory))
getting bulk failure in filebeat when checking in elastic search log its bulk rejected.
what should be the queue size for production ? currently using write thread popl with 2000 queue size.
getting data loss