Hi Guys,
Right now i have 1 index with 5 shards which is storing the multiple tenant logs. now I want to create indexes in elastic cluster for each tenant and I need to keep the docs for 1 year or 6 month time period based on requirement. splunk forwarder is my default log forwarder for splunk as well as graylog+elastic cluster. please help me to create individual indexes for tenants and how to redirect the log to respective tenant index.