

Thank you for sending me the information about my question on this case. I learned all of your answers.
Your insights and summary are beneficial.
Best regards,
2/ Now time to back to work on my question that I am unable to answer.
I am facing the issue with [1000]/[1000] maximum shards open
Prod Evn: We are planning to triple the number of agents very soon, 1200 agents in six months.
wazuh 4.1.5 (Wazuh Cluster (1 Master Node + 1 Worker Node)) + opendistroforelasticsearch Cluster ( 1 Master Node + 1 Data Node)
400 agents + 20 logs files from routers
used ram 16/24
cpu load average lowused hdd 700G/1TB
3/ As far I understand, we can fix this issue by adding more nodes to Elasticserach cluster & Increment the max shards per node ==> Do we have a formula or simulator to calculate the hardware system requirement & data node, increase the shards limit by nodes, and be careful with business requirements? If not, could you please suggest max shares per node and what max data node should I do?
4/ Do we have a solution/command query to monitor shard per node, ES Cluster, I'm considering with the Grafana Prometheus, not sure we can do that with a few simple command, that would be nice if you could point out to me.
5/ How to query GET snapshot to grep index on the DevConsole. I'm looking for that.
I'm looking forward to hearing from you soon!
Regards,
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
wazuh+un...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/wazuh/790655fc-f141-48b7-80a0-dfd093607627n%40googlegroups.com.