Elastic siem and EDR architecture validation

please let me know isthis correct diagram for 50gb par day dat ingestion and i need DC and DR both

Hello and welcome,

Is this estimate of 50 GB/day correct? This is very small and your configuration is extremelly overkill for it.

How did you arrive to this number?

The overall design is ok, I have a similar one specially the logstash + kafka + logstash, but some things are a little confusing.

First, your logstash layer that act as producers do not exist in your DR, so your DR would be only for querying the existing data, right?

Another thing, Fleet is used to manage Elastic Agents, and Elastic Agents can be enrolled to one cluster only, there is no reason to have DR fleet servers unless every time you change to DR you reenroll all your agents into the DR cluster.

Also, as far as I know MinIO is deprecated, what would be the use here? Local object storage compatible with s3 api to use on frozen tiers? I'm not sure what is being used on-premises now, but since this requires a paid license it may be better to reach to elastic to have some help designing your cluster.

this arch recommended by OEM for multisite having DR and below is the sizing details also recommende by OEM

Aspect
Data Ingestion per day 50 GB
Retention Period 1 year - 10 days hot | 20 days cold | 335 days frozen
Deployement Self managed
Total RAM (GB) Total Storage (TB) Object Storage(MinIO) (TB)
Hot 30 0.8
Cold 16 1.2
Frozen 8 0.6 10.1
Kibana 8
Total RAM 62
BOQ
Data Tier Nodes Total CPU Total RAM Total Storage(TB) Object Storage(TB) Type of Disk
Hot 2 16 30 0.8 SSD/NVME
Cold 2 8 16 1.2 Dense HDD
Frozen 1 4 8 0.6 10.1 Object Storage
Non Data Nodes nodes Total CPU Total RAM Storage(GB) Type of Disk
Kibana nodes 2 4 8 300 SSD/NVME now let me know how shall i create architecture for customer having 60 endpoints from where we will take data and this is OT/IT SOC setup in which they have below telemetry

Requirement
Detail
Current SIEM ingestion
Approximately 50 GB/day
EDR scope
35 workstations + 25 servers, including 4 Linux servers
Current SIEM source
Netka Syslog