Is there a recommended "minimal" ELK architecture for production? I know, I know, this depends
In my case, I want to set up a central ELK stack where we can send our application logs (via rsyslog) to the stack. Here is my production environment
- 6-8 customer sites
- Each site will have up to 6 application servers
- Each application server can have 'up to" 150MB of "rolling" log data
- We have to retain the data for up to 3 months
I'm thinking, 4 servers?
- 3 Elasticsearch servers to form the cluster
- 1 server for both Kibana and Logstash
Feedback? Is there a guideline available?