I would like to build my first ELK cluster in Azure in order to collect and analyze logs from VM's and firewalls. I used ELK Azure template and I created 3 masters, 1 data, Kibana and Logstash nodes.
I would like to monitor ~100 VM's and ~20 network devices.
I plan to keep logs 30 days.
Most of VM uses Windows Server so I plan to use winlogbeat to send logs to ELK.
How many nodes I should use for cluster?
It's very hard to calculate storage size I will need.
Do you think the above scenario is enough? or I should use a different schema?
I used azure Ds1v2 for all nodes. (Data + 512 GB drive ssd)
Thanks for help and advice.