I just upgraded from Kibana 4.1 to Kibana 4.2.
By the way, I also upgraded Logstash and Elasticsearch to 2.0 (from 1.x).
I use this solution to collect logs from firewalls through syslog input and then some simple logstash filtering.
I also use curator to close indices older than 2 days in order to keep a reactive solution.
My solution is hosted on a DELL dedicated server with 4 core CPU and 6 Gb RAM (enough to keep 3 indices open).
Now that I have upgraded, I am facing 2 major problems :
- I have about 3 minutes delay between the time where the message is issued and the time it appears in kibana
- the messages volume has really really fallen down, see the chart below showing the message volume for the last 24 hours. One can see that the message volume has dropped significantly after upgrade.
I don't where to look to see where my problems come from. I imagine that Elasticsearch needs optimization. But how ?
I looked in the log files, fournd nothing special in them..
Please help !