We have a computer (C1) with elacticsearch and Kibana. Other computer (C2) with logstash installed.
Network computers send syslog messages to logstash. Logstash send messages to C1.These logs have some información: User access, equipment failures. etc....We keep this information for 6 months.
We need keep some syslog messages (those with facility 4 or 10) during 5 years, so I was thinking deploy extra computer (C3) with elacticsearch and kibana. C2 would send syslog messages (those with facility 4 or 10 facility 4 or 10) to C3 also.
is it a good design? other alternative?