22 million daily from a small number of devices sounds like you are doing verbose log levels from a firewall or two. No way should a network of switches and routers generate that number of logs.
Is there a regulatory or legal requirement for you to collect that verbose a level of logging?
That aside, customers with that volume of messages typically use a separate dedicated tool such as Splunk to ingest that much data.