So, and estate of Winlogbeat agents on endpoints all pointing to a multinode Elasticsearch cluster and for insight into the data you have Kibana.
We always recommend testing such. That way you can get a base line for how well a single node cluster will cope with the number of shards versus the resources allocated.
What we have to go on thus far is winlogbeat-security-* aptly named daily indices, up to 200GB per day.
With a retention period of 31 days, 6.2TB
So say you want to
resource performantly keep somewhere between 500-1TB of data per data node.
Lets say 1TB, which asked for 6-7 data nodes with 1TB of SSD disk plus 20% overhead. Being mindful of watermarks. We have not spoke about master nodes or sole ingest nodes.
Presuming this will be an index heavy cluster opposed to a search one. You will opt for indexing performant tuning.
RAM 60+GB Whatever you feel comfortable with but as long as you set 50% to the Elasticsearch heap but no higher than 30GB!
You will want to consider how much enrichment you want to do to your events as they come in via winglogbeat and or logstash.
Windows server support.
What do you want to gain from X-Pack. I personally believe x-pack is cool, thus would recommend alerting, monitoring, security, and later on machine learning to do cool things find out a baseline for how many windows laptops you are collecting events from who's mac addresses were residing in one location on a given day the same day every week and send an alert when things start to look anomalous.
Pricing here but also all the above is an insight to the depth of support you may get when you get a subscription with us