I'm new to elasticsearch :).
i'm actually planning to deploy a graylog instance for managing about 100GB / day of log and keep them for a year, so a total of 36/40TB of Log (~5000 msg/s).
The main usage of the solution will be to index log everyday, with some dashboards and smarts alerts on the last 24h.
The other usage by 2 or 3 peoples search over multiple week of log.
So i don't really need High availability (graylog server have some cache to handle elastic unavailability), i only need to index and access a big amount of data.
Is it possible to get a signle elastic search big server bi-18core 253MB ram and 50TB of storage?
My goal is to simplify maintenance and limit price of solution.