3 ms·
What about index mapping, how many primaries, how many replicas, index rollover. Is your hot tier optimised for ingest, warm tier optimised for querying, and co
by nullify88 4y ago
What about index mapping, how many primaries, how many replicas, index rollover. Is your hot tier optimised for ingest, warm tier optimised for querying, and cold tier optimised for storage?
There's so much to think about to get Elasticsearch running "optimally" and to keep it that way.
It highlights the operational cost of running Elasticsearch.
- EdwardDiego 4y agoAny tool handling large amounts of data has an operational cost.
- nullify88 4y agoSure but in the end it boils down to whether that operational cost is worth it for the value received. Tools like Loki, are worthwhile alternatives for centralising infrastructure logs with lower operational costs.
- dig1 4y agoES isn't cheap to start with, and I agree with you on that, but it is straightforward to scale after you go above 3-6 nodes. ClickHouse is easy to start with (a single server), but not so much with unobtrusive scaling up or down. > What about index mapping, how many primaries, how many replicas, index rollover. Is your hot tier optimised for ingest, warm tier optimised for querying, and cold tier optimised for storage? Yes, there are details in this, but like every truly distributed system, you can't just plug it in and hope it works in the most optimal way. Also, regarding hot/cold storage, AFAIK, ES can do it after the fact, but with CH, you need to plan it in. > Sure but in the end it boils down to whether that operational cost is worth it for the value received. And as ELK is commonly used to centralise infrastructure logs, tools like Loki, SigNoz are becoming worthwhile alternatives. Actually, it boils down to whether you plan to grow or not, and tools like SigNoz or Loki has their place for sure. For example, for centralized logging, if you have a few servers and keep it that way for the next N years, ELK might not be for you. But, if you suddenly end up with 100 servers, ML team and would like to drill through logs and other data to get more insight on everything, moving to ELK will be way pricier than starting with it.
- nityananda123 4y agoHi, I think this question is pointed towards Elasticsearch, But here are some points for SigNoz. ( I am one of the maintainers at SigNoz) > Directly ingesting to disk(hot tier) is faster than directly ingesting to s3(cold storage) > The query results were an average of cold + hot run ( for elk as well ). We didn’t have an explicit concept of warm storage for SigNoz in our benchmark. > The query perf for logs with cold storage is almost similar to hot storage, but the operational cost will reduce with cold storage. So ingesting to host storage and moving to cold storage after a certain amount of time is a good option for Signoz.