Assessment dimension
Continue to build ELK/EFK independently
Evaluate Guance log management platform
Control and accountability
The team manages the pace of clustering, sharding, indexing, plugins, and upgrades, while also taking on operational responsibilities
The platform provides capabilities for collection, parsing, querying, retention, and governance, with teams focusing on managing data strategies
Data range
Focusing on log and document retrieval in Elasticsearch
Logs can continue to be associated with Traces, metrics, pods, hosts, RUM, alerts, and events
There is already investment
Maintain existing pipeline, indexing, and query habits
You can first bind external Elasticsearch / OpenSearch indexes or doublewrite authentication, without requiring a one-time switch
Cost assessment
It is necessary to simultaneously account for computing, storage, networking, backup, and platform personnel
Requires actual writing, retention, querying, and service boundary accounting; It's not just about a single storage unit price