20. Our Cluster
56 indexes
for customer search
26 indexes
for intranet
4 indexes in 14 languages up to 2.5 million docs per index
3 nodes 8.1 GB
2 replicas, no sharding 10 million documents
21. Our migration strategy
• Unique index names
using timestamp
• An alias <name>_live points to the
current index
• For migration we use temporary alias
names <name>_temp
23. What do we do with logs @ GYG ?
• Debugging • Business
Intelligence
24. Motivation for a new infrastructure
• SSH to host no longer an option
• Local storage in the cloud is limited
• No one uses outdated tools
• Fault tolerant trustworthy logs are a must!
• Redundancy, Auto failover, Monitoring
25. Logging infrastructure - FLKLEK
Two m4.2xlarge AWS instances
(One tie breaker instance in Digitalocean)
26. The Numbers
120 GB 20 Mio
elasticsearch store size log lines /day
42 5.5K
nodes avg. logs /second
27. Lessons learned
• Large documents affect ES performance
• Dynamic mappings are a pain
• Beats don’t play well with file rotation
• Kibana is a powerful tool