Hi,
I've just enabled an ingest node pipeline for a subset of logs ingesting to one of our 5.6.3 clusters. The pipeline looks like this:
```
{
  "test" : {
    "description" : "Test Logging Pipeline",
    "processors" : [
      {
        "set" : {
          "field" : "pipeline",
          "value" : "test"
        }
      }
    ],
    "on_failure" : [
      {
        "set" : {
          "field" : "_index",
          "value" : "failed-{{ _index }}"
        }
      }
    ]
  }
}
```
After enabling the pipeline logging stats look like this over a 90 minute window:

- Test log source: 33.5 mill down to 68.5k
- Other sources: 36.7 mill down to 247.5k

We're running with 12 data nodes and 3 ingest nodes. Data nodes are quad core with 16GB HEAP and ingest nodes are dual core with 12GB HEAP. On beginning of ingestion to the pipeline load averages on the data nodes rose to as much as 7. All of our indexers send their logs via the ingest nodes. The majority are not using ingestion pipelines....

So, I'd like help to understand the collapse in throughput here?
Regards,
D

---