We have the cluster - 1 master nodes and 3 data nodes. Every Data nodes have cpu - 12 cores, RAM - 48 GB (Xms Xmx 16 GB), Disk - 450 GB SSD . Three Indices are created every day – logstash, elasticflow and elastalert. The total number of indices is 47, shards - 130, Documents - 1 billion, Data - 700 GB.
Average size of indices logstash is 60 GB, numbers of documents 60 million. When I am making a request in Kibana in indiced logstash for the last 72 hours and i'm getting "Data might be incomplete because your request timed out".
Could you tell me what cause that problem?