Hello,
i have install the ELK Stack for apache and php logs. My logstash is connect to my elasticsearch.
At present, logstash create a daily index for elasticsearch.
I have 600Mb of logs per day, and we want to keep the logs for 30 days ( ~18 Gb).
The shards can't support 45Gb of data, but it is a good things to have just one shards per daily index ?
Because i dont know if the best is too create juste one index logstash with 5 shards of 3.6Gb or create a daily index with just one shards of 600Mo (it's easier to delete index to old after 30 days than data on shards ?)
Ps : i have just one node
Thkssssss