I'm currently working on a system that gathers IDS events and stores them in an ELK stack.
For the IDS and event storage we have one big server. (128 GB ram, 8 core Xeon, 12 Disk (10K RPM) raid 5 array)
To give you an idea on the size, it stores about 6 billion documents on average.
At the moment our ES cluster consists of only 1 single node. However, the performance of ES is underwhelming.
Would it be beneficial to set up virtualisation and have the 1 physical server run multiple nodes?