I got a monster server from my management to build a ELK stack. They are not after highly available cluster. They are good with one server too. The following is the specs:
Processor: Intel XEON 2.2Ghz (2 Processor)
Memory: 32GB (soon it will be 128G)
System type: 64 bit
OS: Windows Server 2012 R2 (yes we can't build Linux based ELK)
Disk: Well, disk configuration is interesting and overkill but this is what I got. Here is the complex configuration:
There are total 72 SSDs 800GB each in this server. There are three RAID controllers that are configured as RAID 1. Each RAID controllers are assigned 24 SSDs.
In Windows, 9 volumes are stripped in to 3, 17TB each using dynamic disks. So, currently I can see 3 volumes of 17TB and C: drive of 700GB.
Now, we have a plan to dump all of all Windows security events regarding authentication and file auditing, Microsoft Exchange messaging logs, SharePoint, and IIS logs to this server.
Should I install Logstash on same server or any virtual server. I believe, I should install Kibana and Elasticseach on this server. How should I configure Elasticsearch as above-mentioned scenario?