I have distributed environment with 2 indexers (each has 48 vCPU, 64gb RAM), which are ingesting 200 gb logs/day (each indexer).
I want to send to them another 200 gb syslog logs per day (for each indexer), but I want to filter the logs before indexing. I would index only 10% of 200gb of that additional syslog logs at each indexer, so 90% would be rejected.
Could you please tell me what are hardware requirements for such setup? I couldn't find any hints.
... View more