Thank a lot for a quick reply!
<logall_json> is enabled to have all raw logs stored as per the compliance requirement. 90 days older archive logs are then dumped to the remote location. Is there a different approach should I adapt to achieve this? I would like to explore other options if any.
I read in multiple threads/posts that once the indices grow bigger, it becomes difficult to manage and increases the searching time. Hence my idea was to move 60days older data from wazuh-alerts-* to wazuh-archives-*. May be my understanding is wrong!?!? Now get the relation between logall_json & wazuh-archives-*. If asked during the audits to show old logs, I can import archived zips and present the data to the auditors, right?
I checked few posts about policies you mentioned above; query here is, where does this data go after 60days? Will it be there in wazuh-alerts-* itself or it will create another index pattern? This is kind of confusing for a noob like me.
This hot / cold would be a storage parameter right? How would I be able to check my configuration and decide further course of action?
Regards, KS