Hi people !
My situation: I have 2 logstash-forwarders sending network devices logs to an ELK server. In the past I did create the needed indexes based on time ( YYYY+MM+DD), but I detected that the performance of the server goes down with this config, and i changed it to static indexes, the performance problem was resolved with this change.
But, now i have big indexes on the elk server and i need retrieve data from them to migrate or delete it.
at the momment i was deleting the indexes and start them again from the scratch , but i want to have capability and the knowledge to select a specific info from an index and make different actions with it.
Thanks in advance