Really depends on the size of each log and the complexity of the tokenizers. With 1 core you have time budget of less than a millisecond per log statement for processing and that doesn't include the relevant ES/Lucene operational overheads.
This is extremely doable for some workloads, but not others. Really depends on what you're stuffing in.
This is extremely doable for some workloads, but not others. Really depends on what you're stuffing in.