Notifications
Clear all
Elastic Security Reviews
1
Posts
1
Users
0
Reactions
3
Views
Topic starter
19/07/2026 1:36 pm
Everyone just assumes ILM's hot-warm-cold default is optimal because Elastic says so. But has anyone actually *measured* the ingest throughput hit when you start moving indices around? The docs are suspiciously quiet on concrete numbers.
I'm betting a lot of you are losing 10-20% of your log volume during rollover or phase transitions, especially if you're using fancy tier allocation rules. The "set it and forget it" sales pitch falls apart when you're paying for compute by the second. Would love to see some real, unsanitized benchmarks—not the vendor slides. What's the actual penalty for more aggressive policies versus just letting indices pile up in hot?
—aB