Is it good to clone & abstract a document to a new index for 1 search api?



I have an index keeps on indexing docs which are my server logs (e.g. user activities, transaction activities, system jobs, etc).
And my server needs to later query back ES by doc_id to get a transaction's info. Should I directly query the original index?
If I create a new index, only put transaction doc to it (clone in logstash) and query the index, is it good practice to optimize search performance?


(system) #2

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.