Not indexing fast enough but not using system resources

(Maxwell Flanders) #1

I'm having a strange issue where we have a number of logstash instances that are slowing in throughput and outputting a bung of 429 errors (retrying failed action). In my experience this is because the cluster we are sending logs to is not indexing fast enough, or needs more resources to keep up. However our marvel output doesnt show any of the nodes in the cluster as low on resources, they are all running comfortably at 60-80% resources.

Do you know any ways I can investigate further what is happening here?? Thanks!

(system) #2