I have setup a EFK system just for testing at the moment.
It's running in a VM with not much RAM and I am having problem with the
elasticsearch process because of this. The VIRT = 12GB which is
approximately the total size of the indexes.
My indexes are split by date like so...
logstash-2014.06.01
logstash-2014.06.02...
and so on. I'm guessing elasticsearch is trying to hold all of this in RAM.
Is there a way I can setup elasticsearch to only search a specific index
(or number of indices)? Is it just a case of archiving the logs I don't
want ES to deal with? Ideally I'd like to work with only the last day or
two of indexes which will hopefully all fit into RAM.
I have setup a EFK system just for testing at the moment.
It's running in a VM with not much RAM and I am having problem with the
elasticsearch process because of this. The VIRT = 12GB which is
approximately the total size of the indexes.
My indexes are split by date like so...
logstash-2014.06.01
logstash-2014.06.02...
and so on. I'm guessing elasticsearch is trying to hold all of this in
RAM. Is there a way I can setup elasticsearch to only search a specific
index (or number of indices)? Is it just a case of archiving the logs I
don't want ES to deal with? Ideally I'd like to work with only the last day
or two of indexes which will hopefully all fit into RAM.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.