Our goal is similar to discussed in this thread Machine learning - host stopped sending logs or events - we're trying to send alerts when certain hosts or components stopped to send data or we have anomaly in data volume.
There are about 5 indices, with about 30 log types, tens of hosts.
We created multi-count job, using "type" as partition_field_name. But what about per-host issues? Should we use "host" field as influencer or we can use "host" as a "sub-partion"?