Feedback for 100Gbit/s Elastic SIEM design (which includes Suricata)

Is cross-posting allowed here? If so, then I would like to hear some feedback on the topic below. You may reply on this Discourse instance, or the Suricata one of course.