I am currently working on the architecture design for our Splunk platform in AWS
90 days of local cache is not mandatory for ES. It may, however, be necessary. It depends on your datamodel accelerations. By default, many have a summary range of 3 months, which is where the 90-day recommendation comes from. If you've tuned your datamodels down then you may get away with a smaller cache.