I have recently upgraded my production cluster to 6.5.4 Seeing there are so many delays in ingesting high volume logs in Cluster.
I'm getting around 3tb from 560 filebeat clients which use multiple prosecutors among them 2 logs are very high volume of logs which generates 1 to 2tb index
which shows me they are behind in ingesting
here is my current data flow to elasticsearch
560 filebeat => 3 Logstash server => Elasticsearch Dedicated ingest nodes 4 => Data 6 data nodes..
not sure why filebeat or logstash is delaying process any inputs will be helpfull
What does CPU usage on Logstash and dedicated ingest node look like? What is the specification of your data nodes? What does CPU, disk I/O and iowait look like on these nodes?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.