Skip to content

Conversation

nastasha-solomon
Copy link
Contributor

@nastasha-solomon nastasha-solomon commented Mar 18, 2025

Description

Contributes to #6526, which requests changes to the note about logsdb and additional information to help users who have enabled logsdb index mode or are considering it. The corresponding 9.0 and Serverless docs are at: elastic/docs-content#878

Preview

Using logsdb index mode with Elastic Security: Made the following changes:

  • Modified the second sentence in the note as per the request in the doc issue. Now it says: Logsdb index mode is fully supported, and is recommended for all Elastic Security deployments. Users with existing Elastic Security deployments are advised to fully understand and accept the documented changes...
  • Added a new section that briefly explains how logsdb index mode might affect CPU and storage usage and links users to an Elastic blog post with recent benchmarks.
  • Expanded the "Runtime fields" section by adding guidance for handling runtime fields with scripts that reference the params._source field.

@nastasha-solomon nastasha-solomon added Team: Detection Engine Priority: High Issues that are time-sensitive and/or are of high customer importance Effort: Small Issues that can be resolved quickly v8.17.0 v8.18.0 labels Mar 18, 2025
@nastasha-solomon nastasha-solomon self-assigned this Mar 18, 2025
Copy link

A documentation preview will be available soon.

Request a new doc build by commenting
  • Rebuild this PR: run docs-build
  • Rebuild this PR and all Elastic docs: run docs-build rebuild

run docs-build is much faster than run docs-build rebuild. A rebuild should only be needed in rare situations.

If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here.

@nastasha-solomon nastasha-solomon marked this pull request as ready for review March 18, 2025 19:30
@nastasha-solomon nastasha-solomon requested a review from a team as a code owner March 18, 2025 19:30
Copy link
Contributor

@marshallmain marshallmain left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me!

@tylerperk
Copy link

Hi, I see that the preview docs linked in this PR say "To learn more about how logsdb index mode optimizes CPU and storage usage..." but the blog that it links to doesn't talk about CPU optimization.

[[logsdb-cpu-storage]]
== CPU and storage

Logsdb index mode significantly reduces storage needs by using slightly more CPU during ingest. After enabling logsdb index mode for your data sources, you may need to adjust cluster sizing in response to the new CPU and storage needs. To learn more about how logsdb index mode optimizes CPU and storage usage, check out https://www.elastic.co/search-labs/blog/elasticsearch-logsdb-index-mode[our blog].
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey, @tylerperk thanks for the feedback. Would you prefer that the docs link to a different blog? Or are you instead recommending that the last sentence be revised, for example:

Suggested change
Logsdb index mode significantly reduces storage needs by using slightly more CPU during ingest. After enabling logsdb index mode for your data sources, you may need to adjust cluster sizing in response to the new CPU and storage needs. To learn more about how logsdb index mode optimizes CPU and storage usage, check out https://www.elastic.co/search-labs/blog/elasticsearch-logsdb-index-mode[our blog].
Logsdb index mode significantly reduces storage needs by using slightly more CPU during ingest. After enabling logsdb index mode for your data sources, you may need to adjust cluster sizing in response to the new CPU and storage needs. To learn more about how logsdb index mode optimizes storage usage, check out https://www.elastic.co/search-labs/blog/elasticsearch-logsdb-index-mode[our blog].

@nastasha-solomon nastasha-solomon merged commit 4c4cc44 into 8.x Apr 21, 2025
4 checks passed
mergify bot pushed a commit that referenced this pull request Apr 21, 2025
* First draft

* Redundant

* Update detections-logsdb-impact.asciidoc

* change tense

* Small fixes

* One more change

(cherry picked from commit 4c4cc44)
mergify bot pushed a commit that referenced this pull request Apr 21, 2025
* First draft

* Redundant

* Update detections-logsdb-impact.asciidoc

* change tense

* Small fixes

* One more change

(cherry picked from commit 4c4cc44)
nastasha-solomon added a commit to elastic/docs-content that referenced this pull request Apr 21, 2025
### Description
Contributes to elastic/security-docs#6526,
which requests changes to the note about logsdb and additional
information to help users who have enabled logsdb index mode or are
considering it. The corresponding 8.18 docs are at:
elastic/security-docs#6639

### Preview 
[Using logsdb index mode with Elastic
Security](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/878/solutions/security/detect-and-alert/using-logsdb-index-mode-with-elastic-security)
nastasha-solomon added a commit that referenced this pull request Apr 21, 2025
* First draft

* Redundant

* Update detections-logsdb-impact.asciidoc

* change tense

* Small fixes

* One more change

(cherry picked from commit 4c4cc44)

Co-authored-by: Nastasha Solomon <[email protected]>
nastasha-solomon added a commit that referenced this pull request Apr 21, 2025
* First draft

* Redundant

* Update detections-logsdb-impact.asciidoc

* change tense

* Small fixes

* One more change

(cherry picked from commit 4c4cc44)

Co-authored-by: Nastasha Solomon <[email protected]>
@nastasha-solomon nastasha-solomon deleted the issue-6526-logsdb-updates branch April 21, 2025 22:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Effort: Small Issues that can be resolved quickly Priority: High Issues that are time-sensitive and/or are of high customer importance Team: Detection Engine v8.17.0 v8.18.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants