Hi Jorg, Thanks for the answer.
The idea behind the restriction of a single machine was for instance to install ELK on a machine and perform fast indexing and review of a set of log. What I got wrong is that the log size can be important (hundreds of Gb) so this architecture will not work, according to the answers above...(goal was to replace Splunk in a similar set up) Thanks, Alex. -- You received this message because you are subscribed to the Google Groups "elasticsearch" group. To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/94ccef51-1cd9-4210-9f6c-d622108633df%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.