It highlights the operational cost of running Elasticsearch.
It highlights the operational cost of running Elasticsearch.
But here are some points for SigNoz. ( I am one of the maintainers at SigNoz)
> Directly ingesting to disk(hot tier) is faster than directly ingesting to s3(cold storage)
> The query results were an average of cold + hot run ( for elk as well ). We didn’t have an explicit concept of warm storage for SigNoz in our benchmark.
> The query perf for logs with cold storage is almost similar to hot storage, but the operational cost will reduce with cold storage. So ingesting to host storage and moving to cold storage after a certain amount of time is a good option for Signoz.
> What about index mapping, how many primaries, how many replicas, index rollover. Is your hot tier optimised for ingest, warm tier optimised for querying, and cold tier optimised for storage?
Yes, there are details in this, but like every truly distributed system, you can't just plug it in and hope it works in the most optimal way. Also, regarding hot/cold storage, AFAIK, ES can do it after the fact, but with CH, you need to plan it in.
> Sure but in the end it boils down to whether that operational cost is worth it for the value received. And as ELK is commonly used to centralise infrastructure logs, tools like Loki, SigNoz are becoming worthwhile alternatives.
Actually, it boils down to whether you plan to grow or not, and tools like SigNoz or Loki has their place for sure. For example, for centralized logging, if you have a few servers and keep it that way for the next N years, ELK might not be for you. But, if you suddenly end up with 100 servers, ML team and would like to drill through logs and other data to get more insight on everything, moving to ELK will be way pricier than starting with it.