Hi, I am considering the ELK stack in a large telco opportunity in the MEA region as the propsosed log management solutions (Humio, Splunk Enterprise, etc,.) are turning out to be expensive in the overall solution approach. Please find my requirements below. I would appreciate it if someone from Elastic guides me with the design considerations so that I will not either oversize or undersize the environment.
- Data ingestion is estimated to be 1TB/day for production and 500GB/day for PoC environment.
- The data retention will be 30 days for production and PoC sites.
- Would like to go with the Ingest node (rather Logstash) in the solution approach.
- Storage for all the nodes (master, data, ingest, coordinator) will come from the external SAN storage.
- It is assumed to gather the logs from Filebeats from the target environment.
- The ELK stack needs to be highly available and should support N+1 redundancy in the production site. PoC site does not require any HA/redundancy and can tolerate failures.
Please let me know incase you need more details.
I would like to know how many VMs needed do I need to carve out and the specifications (CPU/RAM/DISK) of those VMs for both production and poc sites.
Appreciate your quick support. Thanks