This gist contains supporting files for evaluating Elasticsearch index sizes for web access logs.
- Machine with Linux or Mac OS X.
- Local Elasticsearch 5.3.x instance accessible via 127.0.0.1:9200
- The local Elasticsearch 5.3.x instance must have the geoip and useragent ingest plugins installed
- Local installation of Filebeat 5.3.x with environment variable FILEBEAT_HOME pointing to the directory containing the
filebeat
binary.
The test will index data into the following indices, which must not previously exist in the Elasticsearch instance:
- filebeat-test
- filebeat_es_defaults
- filebeat_reduced
- filebeat_best
- filebeat_noall
- filebeat_allquery
- filebeat_combined
Start the test by running the run_test.sh
script.