for moving to the production environment , I am planing to have the below architecture for elk.
I am getting around 5 GB data/day and I am keeping the data for 60 days , after 60 days I am taking the backup of data and deleting the old data using curator
I am having one index/day and I have 30 applications , so total 1800 indices .
I do not want to go for curator because for using curator I will have to create huge number of indices .
(if not using curator I will use delete by query :-
Hardware architecture :-1
Total server = 8
Dedicated master node :- 1 (RAM: 64 GB , storage : 100 GB)
Mater + data node :- 2 (RAM:- 64 GB , storage : 1 TB)
Dedicated Data node:- 1 (RAM : -64 GB , storage : 1TB)
client Node + Kibana(backup) :- 1 (RAM : -64 GB , storage : 1TB)
Dedicated Kibana :- 1 (RAM: 64 GB , storage : 100 GB)
Servers to run Logstash :- 2 (RAM:- 64 GB , storage : 100gb)
Do you see any flaws in above architecture ?
Pls let me know how can I change this even better ?