Graylog troubleshooting

Messages not processing

If there are a lot of messages piling up in Graylog's journal (System>Nodes>nodename>Disk Journal> Utilization) but they are not showing in the Search, you will need to delete the journal folder under /var/lib/graylog-server. Then restart the graylog.

Elasticsearch nodes disk usage above low watermark

Configure lower index retention ( to delete the older ones or delete it manually.

Tested on

  • Graylog 3.3.16
  • Debian 9

