An insurance services provider's ELK cluster had outgrown its storage twice in eighteen months with no clear reason. AceMQ assessed what was actually being indexed and how much of it anyone used.
Default dynamic mapping meant every field in every JSON log line was both indexed and stored, including large nested structures nobody had ever searched. Several services logged full request and response bodies at info level. Retention was uniform across all indices regardless of value, so debug-level application logs were kept as long as audit records. The storage growth curve had no relationship to business growth, but nobody had the field-level data to explain it.
On-premises ELK cluster ingesting application, infrastructure, and audit logs from across the business.
The assessment measures storage consumption at the field level, not just the index level, and cross-references that against search and dashboard usage. That combination shows precisely which fields cost the most and return the least, which turns retention from a policy argument into an evidence-based decision.
The assessment showed that a large share of indexed fields had never appeared in any query. With explicit mappings and tiered retention, projected storage growth flattened enough to cancel the next planned expansion.
Consulting engagement to redesign an ELK ingest architecture around buffered queues, ingest node pipelines, and schema standardization.
Ongoing support across the full ELK ingest path — Beats, Logstash, ingest pipelines, and index templates — with 24/7 coverage.
Whether you need architecture advisory, 24/7 support, or full managed services, AceMQ has the expertise to help.