I would like to take some suggestion to create index pattern in ELK.
As per my current configuration in production, i'm index data in ES by monthly index with 1 Primary Shard and 2 replicas.
Due to that i was faced below in ES,
To avoid such issue i would to break monthly into weekly or Day basis.
I need your input which approach is best approach in production.
Looking forward your inputs on this query