I had to wait for it to fail again.  It looks like it failed on May 30th.  
In the /var/log/graylog/elasticsearch folder the graylog.log.<date> files 
for May 25-29 are all about 400K.  The log file for May 30th is 2.1GB and 
the disk of the virtual appliance is at 100% utilization.  Also, the last 
index folder from before it stopped is 2.8GB in size (my indexes are set to 
roll over at 1GB).  It seems that the "translog" folder in the index shard 
folders are about 700MB each, as opposed to about 12K for the previous 
indexes.

Looks like there are two problems: the final log before failure gets 
bloated while the transaction log for the final index fills with unindexed 
messages(?). 

-- 
You received this message because you are subscribed to the Google Groups 
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/graylog2/c96656d9-ab03-4491-8066-cc10cd4b4af8%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to