<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Tocharian — Elastic engineering notes</title><description>Detection engineering, ES|QL, Splunk migration, and Elasticsearch cluster performance and cost.</description><link>https://tocharian.eu</link><item><title>Making Elasticsearch cheaper without deleting data</title><link>https://tocharian.eu/blog/cheaper-elasticsearch-without-deleting-data</link><guid isPermaLink="true">https://tocharian.eu/blog/cheaper-elasticsearch-without-deleting-data</guid><description>Most teams cut their Elasticsearch bill by shortening retention, which trades away the reason the cluster exists. Here is the order we work through instead.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>cluster-performance</category><category>cost</category></item></channel></rss>