How to Improve Elasticsearch Performance by 20x for Multitenant, Real-Time Architectures
ID: 1c003eb2-c489-59f0-b540-cc2c21134989
STIX ID: report--1c003eb2-c489-59f0-b540-cc2c21134989
Feed Name: Cato Networks
**Executive Summary:** This post describes Cato's Instant*Insight, a multitenant SIEM-like capability, and the architectural and operational changes made to its Elasticsearch backend to improve performance and scalability. It covers using Apache Storm for real-time enrichment, moving from daily to weekly indices with tenant routing to reduce the number of shards queried, trade-offs between hot/warm versus mixed/indexing-and-querying nodes, preferring local NVMe SSDs for better latency, and benchmark results that led to selecting weekly indices on i3.2xlarge nodes, yielding substantially fewer shards and faster query response times.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
