Elastic Cluster Ram, Disk Size 500GB,
3 Master Nodes and 3 Data/Ingest Nodes(1 VCPU, 4GB)
Currently I have Index which is ~200 GB in 1 Shard for 3 month of usage. I would like to delete data for 2 months and leave data only for 1 month based on Timestamp.
What is the best approach for this? Is it just enough to use DeleteByQuery? Should I run this Query for 2 months or it is better to run in portions like day by day?
Will I have issues due to large segment size (~5GB)?