Sitemap

Member-only story

I tried to destroy Graylog — now I monitor with Zabbix.

15 min readMay 12, 2025

--

More than 100X normal load in less than 10 minutes

Experience: that most brutal of teachers, but you learn, my God do you learn
— C.S. Lewis

Pfsense, the popular open source firewall software, is moving away from the legacy ISC DHCP server in favor of the Kea DHCP server. I noticed this warning on a recent upgrade to my firewall. I read through the documentation and decided to do the conversion. I flipped the switch and did some cursory checks on the firewall. Shortly after changing the setting, I received a notification from Zabbix for a high load on my NAS server.

Press enter or click to view image in full size
NAS server running container station

My QNAP NAS server is running Container Station (Docker) and hosting Graylog. Graylog ingests firewall logs from Pfsense and other sources. Looking at the Graylog dashboard:

Press enter or click to view image in full size
Graylog node metrics

That doesn’t look good. The process buffer is 100% full. What’s going on? Looking at the incoming message count on Graylog:

--

--

John Wheeler
John Wheeler

Written by John Wheeler

Security professional, Mac enthusiast, writing code when I have to.