Elastart indices sooo big - how housekeeping them? #15131
-
|
Hi there, Thank you and kind regards! |
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 1 reply
-
|
There are Index Lifecycle Policies in SOC and Elastic Kibana. In brief - you just set up time of life for all indices and can specify for every index separetely. The most space-consuming index is Zeek, so try to reduce Delete policy for this index. Other procedures you mentioned are for SQL databases, while Elastic (which is the base for SO) - is NOSQL database, therefore - database maintanance is performed by Elastic itself and no need for additional procedures. |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
|
Yes sure:
It is Ok (for the moment!) that I have so many errors, since I am testing the alerting. |
Beta Was this translation helpful? Give feedback.
-
|
I decided just to delete the index. |
Beta Was this translation helpful? Give feedback.

I decided just to delete the index.