I have logstash pulling logs from web servers and database servers and is displayed in kibana for the IT department.
The 3 sources of logs:
All data is being pushed to daily logstash indexes.
The development team wants to run a substantial amount of queries against just one subset of data. (web-searches).
While they could do a filter, to only search logs tagged as 'web-searches', I want to know.
- Would there be any performance advantage to putting the web-searches into their own index?
- What guidelines constitute making a new index?
- Do filters slow down searches? or require lots of cpu?