I have 28 types of logs which total up to hundreds of millions event per hour. The indexes are named as following:
For search and aggregation, is there performance difference between using an single
log_* index pattern vs. creating an index pattern for each log type (e.g., log_type_1-*)?
If I use
log_* and search for
type:type_1, would Kibana be smart enough to skip all other indexes that don't contain
type1, or does it have to actually search through all indexes under
I did a quick test on Search and Visualization and didn't see any big difference in response time between
log_type_1-*, but since our logs are growing quickly, any performance tips help alot.