# Guidance on architectural decision making

**URL:** <https://discuss.elastic.co/t/guidance-on-architectural-decision-making/377484>\
**Category:** Elasticsearch\
**Created:** [April 24, 2025, 10:01am UTC](https://discuss.elastic.co/t/guidance-on-architectural-decision-making/377484 "2025-04-24T10:01:40Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![billie007711](https://avatars.discourse-cdn.com/v4/letter/b/e79b87/32.png) [@billie007711](https://discuss.elastic.co/u/billie007711)\
**Post date:** [April 24, 2025, 10:01am UTC](https://discuss.elastic.co/t/guidance-on-architectural-decision-making/377484/1 "2025-04-24T10:01:40Z")

</div>

I want to move logs from

Cloudwatch logs ====\> SELF MANAGED ELASTIC SEARCH CLUSTER

The volume of log is 5TB/day

**Option1:**  
I use aws-forwarder plugin provided by Elasticsearch

> **[Elastic Serverless Forwarder for AWS | Elastic Documentation](https://www.elastic.co/docs/reference/aws-forwarder)**
>
> The Elastic Serverless Forwarder is an Amazon Web Services (AWS) Lambda function that ships logs from your AWS environment to Elastic. The Elastic Serverless...

**Option2**  
I use this flow

Cloudwatch logs ( subscription filter ) ==\> AWS Firehose ==\> S3 \<==== Filebeat ( Elasticsearch )

Any comments/guidance would be appreciated
