Hi Elasticsearch Team,
We have three different machines namely machine A, machine B and machine C.
These three machine are sending syslog data to our logger, which uses elastisearch for storage
In our logger there are three inputs for three machines. (machine A, B and C)
All logs are coming properly and we can view them in UI and they are stored in elasticsearch (one instance only).
Currently we have around 47,285,976 messages in 2,285 ms, searched in 3 indices.
Now my queries are as follows:
Can i archive the data coming from three separate inputs(machines) into elasticsearch for secure storage and re-import back when necessary?
Can i delete logs from elasticsearch based on the inputs(machines from which syslog is pushed to logger) or based on time and date?
Thanks in advance.
framework