What I am doing currently is, fetching logs from one elastic search index. Now I want these logs to be accessible to other users through a good user interface. For that, I was thinking of two options-
- Create a small website to display the logs in a table format after fetching from the source elastic search index
- Use ingest node to query some logs from one index and upload those to a new elastic search index. And using kibana we can already see the logs with a good UI.
Since one of my requirement is adding, deleting columns when visualizing the data, the second option seems suitable for now. But I am concerned about the speed efficiency of both options? Which among the two options is better from the perspective of the amount of time the user has to wait to see the required logs?
I am trying to make comparisons between these two options and finalize one of them. If you can help with other comparative parameters between these two options, it would be a great help.