What is the best practice for organizing indexes for multiple environments of an application such as dev/qa/prod? Is it best to separate them all out into their own index or use a single index?
Thank you
The decision can be determined by answering multiple questions:
Ultimately, it is up to you. The data (most likely) will have inherent features that separate it, either by host, source or sourcetype so, while a separate index is not required, consider the other benefits of separating your data.
Generally it is FAR easier to join together prior to launching than it is to separate afterwards when it becomes necessary for some unforeseen reason so I always suggest we separate on an index-level and also use tags
or eventtypes
to provide automatic delineation when more than 1 index is used in a combined search.
The decision can be determined by answering multiple questions:
Ultimately, it is up to you. The data (most likely) will have inherent features that separate it, either by host, source or sourcetype so, while a separate index is not required, consider the other benefits of separating your data.