A healthcare analytics provider needed multi-year retention for audit reasons but was keeping everything on expensive hot nodes. AceMQ designed an ILM and tiering strategy that meets the retention requirement while moving the bulk of the data onto cheaper storage.
Retention rules were enforced by hand-written cleanup scripts that occasionally deleted the wrong index pattern. There was no warm or cold tier, snapshots were taken inconsistently, and nobody had tested a restore. The compliance team could not answer how long a given record class was actually retained, because the answer depended on which script had last run successfully.
Hybrid Elasticsearch deployment with on-premises hot nodes and cloud object storage available for snapshots and searchable data.
We started by mapping each index pattern to its actual regulatory retention obligation, since several patterns were being kept far longer than required. From there we designed rollover-driven ILM policies with explicit hot, warm, and cold phases, added a snapshot lifecycle policy against object storage, and rehearsed restore procedures until timings were known rather than assumed.
The majority of indexed data now lives on warm and cold tiers, freeing substantial hot-node capacity for query workloads. Retention is enforced by policy instead of scripts, and the compliance team can answer retention questions from the policy definitions directly.
Assessment of an oversharded Elasticsearch cluster where cluster-state size and pending task queues were driving master instability.
Ongoing 24/7 support for an Elasticsearch estate suffering repeated parent circuit breaker trips and long garbage collection pauses under aggregation load.
Whether you need architecture advisory, 24/7 support, or full managed services, AceMQ has the expertise to help.