Hello All,
I have some sizing questions and wanted some input from the community. I'm pretty sure the answer, like most, will be "it depends", but I'm looking for some pointers that I feel are outside of my technical skills. The scenario I'm working with starts with 5 logs. My metric calculations will require me to correlate data from 1 or more logs, even all 5 in some cases. My questions are these:
1. Is it better to create 1 log per index and end up with 5 total indexes, or like the _internal index, should I create a single index for all logs?
2. Are there any specific considerations that would drive this decision? For example, data retention policies are the same for all logs.
Thanks in advance!
Best regards,
Andrew
↧