Thanks for your support in advance. I am using Graylog 2.x very well in my company. It is being used as a company-wide log monitoring system on AWS. I figure Graylog is a well-made and really nice program. And also I am a newbie in this community
- Elasticsearch has a kind of soft limit on its cluster size.
- Elasticsearch guys said that about 150~200 data node is maximum because of their gossip overhead; I am using 150 data node now.
- So I think the best way to scale out the elasticsearch cluster is, making multiple elasticsearch clusters not adding more nodes.
- But it seems that Graylog now supports only one elasticsearch cluster.
Do you guys have any plan about multi elasticsearch cluster support or cross-cluster search feature of elasticsearch?
But ‘Cross Cluster Search’ feature of elastcisearch is in beta and is subject to change, so I think this feature is unstable to rely on. So, in my opinion, the best way to support muti elasticsearch cluster is to make Graylog’s own way leveraging its Mongodb config store. It would be really great if I can use different elasticsearch cluster per stream.
Appreciate for your help or reply.