We are looking at a production implementation of ELK to replace our logging solution. We are looking at creating daily indices, which would make it easy to manage them.
Here is the issue we would like to have 90 days worth of logs/ indices on the faster disk. And would like to 365 days worth indices in slower disk. But we need all the logs to be searchable.
Is it possible to have 2 replica shards for every primary shard, allocate one of the replica shards to the slow disk( which will also have ES instance running on)?
Can we customize the search engine to not to read from the slower disk node unless we specifically say so?