I really need some closure on the difference between Indexed and Archived data.
Right now my ELSA (running for 6 months) shows me 1 billion logs indexed and 1 billion logs archived. If that is the case, why would I ever want to search in the archive?
Does the archive hold more data than the index?
I just don't get the point search-wise.
Another thing that really has been bugging me is, on how to make a query of all dstip seen today using the bro.conn.
ELSA will usually crash/timeout if I set the limit value. It's not exactly a heavy query.
Cheers.