I attended elasticON in New York yesterday, and spoke with a number of people about a "rollup api" that is currently in development.
We would like to assist with building out use cases and help w/ beta testing.
We have two use cases where a rollup API as described at the conference would be valuable.
-
Metric data - rolling up metrics to 5-minute peaks in order to age out old data would be valuable. Currently, we are using a combination of Elasticsearch and graphite because aggregation queries were increasingly expensive.
-
Summary of firewall traffic patterns for a day, week, month, year, etc. (distinct to and from IPs, ports, protocol, total bytes sent or received, total packets sent or received, whether traffic was permitted or denied, etc.)