I have 1 node elasticsearch cluster, which has 60GB RAM , 1.2 TB disk. I have 1 filebeat and 1 metricbeat index each receiving 6 GB data per day and 1 apm index which is receiving 10GB data per day. I want to retain 60 days' data and delete 1st day's data on 61st day (for each index). If you could propose strategy for implementing this ILM, it would be really helpful. Also I have below questions:
- How much disk space I would require?
- What would be effect on CPU usage for this much data and do I need to increase RAM?
- How increasing shards for indices will help in this situation?