I have some sizing questions and wanted some input from the community. I'm pretty sure the answer, like most, will be "it depends", but I'm looking for some pointers that I feel are outside of my technical skills. The scenario I'm working with starts with 5 logs. My metric calculations will require me to correlate data from 1 or more logs, even all 5 in some cases. My questions are these:
Is it better to create 1 log per index and end up with 5 total indexes, or like the _internal index, should I create a single index for all logs?
Are there any specific considerations that would drive this decision? For example, data retention policies are the same for all logs.