Writing

Notes from production Elastic work

Detection engineering, ES|QL, Splunk migration, and the parts of cluster performance and cost that only show up at scale. Written by the engineers doing the work.

RSS →
Making Elasticsearch cheaper without deleting dataMost teams cut their Elasticsearch bill by shortening retention, which trades away the reason the cluster exists. Here is the order we work through instead.cluster-performancecost