We are trying to evaluate elasticsearch for keeping up our events and very impressed so far.
Though there are two issues we need help with
- We need to only keep X no of events per MAC address and old events should be purged. Since MAC could be in order of thousands obviously having separate indexes per mac is out of question.
I am assuming that this should be possible using aggregation and pipelines but now sure how - Is there a way we can get metric of No of query served during a time period, we need this info for our own benchmarking purposes.
Thanks in advance.