Sometimes when we swich on log monitoring on new sources we face reqularly trimmed logs however we do not see any resouce issues on dt managed servers (self portection works well :-)).
Which resource should be increased in order to get more cluster managed limit events rate? CPU or RAM or both? Which one has more influnce on it?
Attached a time period when logs were trimmed without managed resource issue.
Managed: (8vcpu, 66GB RAM) *3, cluster managed limit for evenets 26,500 per/minute - > 20k allocated for this environment.