The Elasticsearch Data Model is almost identical to the Thundra Monitor Data Model with the only difference being some enrichment of data for Kibana specific processing. The Thundra Integrator for Elasticsearch will create five indexes in your Elasticsearch instance and these indexes are rotating daily.
We are using
_ instead of
. while defining tags in our data models. Because
. has a special use in Elasticsearch so that using
. while defining data keys is not ideal. Remember that if you are about to define custom tags in your data models please avoid using
. while defining key values. E.g. instead of