I have a 5 node ES cluster (each node is single core and 4Gig RAM) which is receiving data from metricbeat and winbeat via logstash. The data generally amounts to 175 GB and is stored in a per-day index.
Even when I search for a data for an hour, our queries are taking very long time.
Below is our config :
discovery.zen.ping.unicast.hosts: ["node1", "node2","node3", "node4", "node5"]
Am I doing something wrong?
Do I need to customise my mapping? Do I need to store a week/month's data per index?