Hi I have a scenario where I would have logs from 100 node horizontal scalable Cluster , out of below options which would be the better option to achieve efficient and high performance search ?
1)Creation of 1 Daily Index of logs with 5 primary Shards per node of cluster , Means 100 indices for 100 nodes .
2)Creation of Index of Logs from the subset of nodes like 1 daily index (5 primary shards ) per 10 nodes of Cluster , means in this case 10 daily Indices for 100 node cluster .
Logs would be searched from all the indices . Please suggest