We have an Graylog index that will receive about 300 million messages / 24h.
Total amount of data is approx. 54GB /24h.We would like to have this searchable for 3 years.
he setup we intend to use is:
1 index with 5 shards and 1 replica.
Max number of indices:1096
Index retention strategy: Delete
This will result in the index for each day(24h) will be aprox 300 million messages/54GB
Is this setup feasible or should we do it some other way?
Thankful for any suggestions!