# Newbie question - need suggestion - NFS share + 1 node

**URL:** <https://discuss.elastic.co/t/newbie-question-need-suggestion-nfs-share-1-node/243534>\
**Category:** Elasticsearch\
**Created:** [August 3, 2020, 9:50am UTC](https://discuss.elastic.co/t/newbie-question-need-suggestion-nfs-share-1-node/243534 "2020-08-03T09:50:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dan00bielb](https://avatars.discourse-cdn.com/v4/letter/d/6a8cbe/32.png) [@dan00bielb](https://discuss.elastic.co/u/dan00bielb)\
**Post date:** [August 3, 2020, 9:50am UTC](https://discuss.elastic.co/t/newbie-question-need-suggestion-nfs-share-1-node/243534/1 "2020-08-03T09:50:50Z")

</div>

Good morning community,  
i am a newnubbie to ES and i would like a design suggestion from you.  
We need to index 5 years old logs taken from a SIEM from a subset of applications, we have **one server** (system spec should be defined) and an attached **NFS NAS storage of 5 TB**. The logs size to be ‘uploaded’ to ES once a day (we though to retrieve and upload the data **via API** ) each day are few, approx 400 MB per day; so basically 712GB per 5 years. I have the following questions, i hope you can help me understand better and give me some advice:  
1- It is feasable to use the 5TB NFS as a index data store nonetheless the few data required to be indexed? As far as i understood NFS datastore are a nono in ES.  
2- All the log data from 5 years back should be searchable and indexed; an index of almost 1TB is feasable? Or it is adviced to define an index for each log source and/or for each day/week/month? What are your suggestion about index and shards to be defined?  
3- With the data required to be uploaded and indexed, what server (1 node) specs do you suggest? 8cpu and 32GB RAM?  
4- If the NFS datastore is not an option how can i use it? Store Index snapshots maybe?

I hope my questions are clear enough and that you can help me on my doubts.  
Thanks,

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 3, 2020, 10:00am UTC](https://discuss.elastic.co/t/newbie-question-need-suggestion-nfs-share-1-node/243534/2 "2020-08-03T10:00:17Z")

</div>

> [@dan00bielb](#):
>
> 1- It is feasable to use the 5TB NFS as a index data store nonetheless the few data required to be indexed? As far as i understood NFS datastore are a nono in ES.

NFS is [not recommended](https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-indexing-speed.html#_use_faster_hardware) as it can cause performance problems and I believe potentially also corruption (could not find reference now though).

> [@dan00bielb](#):
>
> 2- All the log data from 5 years back should be searchable and indexed; an index of almost 1TB is feasable? Or it is adviced to define an index for each log source and/or for each day/week/month? What are your suggestion about index and shards to be defined?

Use time based indices, e.g. an index per month.

> [@dan00bielb](#):
>
> 3- With the data required to be uploaded and indexed, what server (1 node) specs do you suggest? 8cpu and 32GB RAM?

Sounds like a reasonable starting point.

> [@dan00bielb](#):
>
> 4- If the NFS datastore is not an option how can i use it? Store Index snapshots maybe?

Yes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2020, 10:00am UTC](https://discuss.elastic.co/t/newbie-question-need-suggestion-nfs-share-1-node/243534/3 "2020-08-31T10:00:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
