We're running multiple webshops on the same application. And we're logging some API calls we're making (with separate index for each logging use-case). We have one shared logging elasticsearch cluster.
But for the cluster, is it better to have one index with documents from all the webshops, or to split them up with one index each (still separating the separate logging use-cases)?
At the moment we have them split up:
But with ~10 different webshops, the amount of indices on our cluster keeps growing. While the indices are not that big.
Biggest index is 2.1gb, but the median is at 98mb.