Hey guys,
since i still pretty new to this topic, i wanted to know if the following would be Possible:
I've got a costumer who has different retention periods for different logs.
In this case, the logs concerning the internet searches have to be stored 12 Months instead of 3.
So as i know, i can manage it via the rollover-policies, but the thing is that the Index (Logstash) which holds the data about internet searches, is the same as the verbose output of the virtual cluster. Can i somehow configure it that, that the logs concerning the webfilter will be handled in a different index so i can create a rollover-policy over 12 Months?
Sorry if that's a dumb question. Not my topic usually.
Kind regards,
Moritz Kiesewetter