Hi there,
I've thinking about a little validation of my ELK-Stack Installation... A Word and a blow!
The differenc between a sepaerate logfile and indexed events is very very high:
Logfile: 24Million lines and Index: 8Million Events...
Yes, I'm well aware that logging traffic is udp, mainly... And up to 5% packetloss will be fine for this case...
Please provide me to finding the bottleneck and a solution for this issue...
ES is configured with Max HEAP Size of: 24G
LS is configured with Max HEAP Size of: 8G (I've never seen more than exactly 1GB reserved)
The deployment is on one single VM with 2x2 Cores and 64GB RAM, OS RedHat.
...