Re: [graylog2] Re: Design question concerning Inputs

2014-12-16 Thread Troy
Kay, If I have an input that has say 10-15 "base" extractors and I want to break it into separate inputs to tag the sources as you mentioned, so we would be duplicating the extractors across multiple inputs. Does the duplicate extractor processing add substantial overhead? In general, what is

[graylog2] Automatically deleting messages, which are too large for the elasticsearch index

2014-12-16 Thread Olaf Heydorn
Hi, we collect a lot of amqp messages from our rabbitmq instance, that is working fine, but we still get a lot of messages, which are too large for the elasticsearch index, which can only accept messages up to 32kb. Is there a filter to delete messages which are too large for the index otherwi