# 2 server ELK cluster implementation

**URL:** <https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308>\
**Category:** Elasticsearch\
**Created:** [February 21, 2020, 8:05am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308 "2020-02-21T08:05:15Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [February 21, 2020, 8:05am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/1 "2020-02-21T08:05:15Z")

</div>

What is the best way to implement ELK stack for a log monitoring system on Windows. I have 2 servers with windows server 2019 installed.

---

<div class="post-metadata">

**Author:** ![BenBell](https://avatars.discourse-cdn.com/v4/letter/b/b38774/32.png) [@BenBell](https://discuss.elastic.co/u/BenBell)\
**Post date:** [February 21, 2020, 9:39am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/2 "2020-02-21T09:39:05Z")

</div>

Hi Nitya,

Is there any way you can increase this to 3 nodes? You will likely run into problems with master nodes and quorum with 2 nodes.

Not knowing anything about your intended use - I would recommend the following as a set of basic rules to try and get you started:

\*Make sure your data is stored on a separate disk to the operating system to reduce latency  
\*Try and make sure you have replica shards for all data in your index definitions to allow for hardware failure  
\*If you are unable to use a load balancer for the 2 nodes, split the client and master roles (point clients via DNS at node-1, establish node-2 as master  
\*make sure you have a good backup routine in place

Sorry, I know a lot of this is just good general advice for all servers - but if you can be more specific in what you want to accomplish from Elastic (throughput, expected data volumes, features you will/won't use, what type of data you want to ingest etc) - I can _try_ to give some more specific advice

---

<div class="post-metadata">

**Author:** ![mattsdevop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattsdevop/32/45160_2.png) [@mattsdevop](https://discuss.elastic.co/u/mattsdevop)\
**Post date:** [February 21, 2020, 2:12pm UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/3 "2020-02-21T14:12:47Z")

</div>

Welcome to elasticsearch @nityaraj06!

It's ideal to run with more than 2 nodes, but it is possible to run a healthy cluster with 2 nodes. You'll need to make 1 of the nodes master eligible and not set the other node to master eligible. This way you avoid "split brain". "Split brain" is a situation where some unplanned failure event happens and both nodes attempt to become master at the same time. Neither node can agree or elect a master node because it's 1v1 vote and a 3rd vote is needed to make that decision of one over another. Since there is no 3rd node to vote, that decision is never made.

Here is the config for setting a master node in the configuration: [https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html#master-node](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html#master-node)

Next, install it and give it a try!

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [February 24, 2020, 8:03am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/4 "2020-02-24T08:03:46Z")

</div>

Thank you for your replies.

I am planning to configure using 2 nodes in the following way - configs from elasticsearch.yml:

**Master node**

- installed Elasticsearch  
network.host: 0.0.0.0  
http.port: 9200  
discovery.seed\_hosts: ["", ""]  
node.master: true  
node.voting\_only: false  
xpack.ml.enabled: true  
node.data: false  
node.ingest: false  
node.ml: false

**Data node**

- installed elasticsearch  
network.host: 0.0.0.0  
http.port: 9200  
discovery.seed\_hosts: ["", ""]  
node.master: false  
node.voting\_only: false  
node.data: true  
node.ingest: false  
node.ml: false

I will install Kibana on the master node.

Kindly let me know how this sounds to you 🙂

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 24, 2020, 8:47am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/5 "2020-02-24T08:47:49Z")

</div>

Why do you want a master only node?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 24, 2020, 9:00am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/6 "2020-02-24T09:00:38Z")

</div>

That does not sound great as any of the nodes going down will cause problems for you cluster.

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [February 24, 2020, 9:50am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/8 "2020-02-24T09:50:40Z")

</div>

I set one node to master and the other to data, isn't it necessary to have one master node atleast? Could you please suggest a basic setup with 2 nodes.

The log files I plan to analyse are mostly under 1gb per month, ~12gb per year

I am using ELK 7.6 version and setting this up on Windows server 2019.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 24, 2020, 10:25am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/9 "2020-02-24T10:25:50Z")

</div>

If you want to be production ready, you need 3 nodes.  
If you don't care about freezing the whole cluster when one node is done, you might use 2 nodes but I'd not recommend that.  
If you don't care at all about your data, one node is enough then. Like in dev platform.

If you go for 2 or 3 nodes, then leave all nodes with node.data and node.master default settings. They will be all holding your data and they will be all master eligible.

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [February 25, 2020, 10:39am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/10 "2020-02-25T10:39:45Z")

</div>

Thank you @dadoonet - I am fine with having 2 nodes for now since this is not a production setup.

I am keeping both nodes as master eligible to handle the master node going down  
node-1

Please suggest if the below design sounds good:  
_ **node-1** _  
cluster.name: es-cluster  
node.name: node-1  
path.data: E:/elasticsearch/data  
path.logs: E:/elasticsearch/logs  
network.host: node-1  
discovery.seed\_hosts: ["node-1","node-2"]  
cluster.initial\_master\_nodes: ["node-1"]  
node.master: true  
node.data: true

_ **node-2** _  
cluster.name: es-cluster  
node.name: node-2  
path.data: E:/elasticsearch/data  
path.logs: E:/elasticsearch/logs  
network.host: node-2  
discovery.seed\_hosts: ["node-1","node-2"]  
cluster.initial\_master\_nodes: ["node-2"]  
node.master: true  
node.data: true

_ **Kibana on node 2** _  
server.host: "node-2"  
server.name: "node-2"  
elasticsearch.hosts: ["node-2:9200"]  
elasticsearch.preserveHost: false  
logging.dest: E:/kibana/logs/kibana.log  
logging.verbose: true

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [February 25, 2020, 11:11am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/11 "2020-02-25T11:11:54Z")

</div>

> [@mattsdevop](#):
>
> "Split brain" is a situation where some unplanned failure event happens and both nodes attempt to become master at the same time. Neither node can agree or elect a master node because it's 1v1 vote and a 3rd vote is needed to make that decision of one over another. Since there is no 3rd node to vote, that decision is never made.

This isn't true @mattsdevop: Elasticsearch will elect a master from 2 nodes just fine. The only drawback with having 2 master-eligible nodes is that it's not resilient and requires both nodes to be available at all times.

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [February 26, 2020, 6:38am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/12 "2020-02-26T06:38:05Z")

</div>

@DavidTurner @Christian_Dahlqvist @dadoonet  
Even after setting both nodes as master eligible why is this showing only one node as master?

ip heap.percent ram.percent cpu load\_1m load\_5m load\_15m node.role master name  
ip1 13 19 0 dilm - node1  
ip2 25 13 0 dilm \* node2

Also could you please let me know how I can test failover conditions with a 2 node cluster.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 26, 2020, 6:56am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/13 "2020-02-26T06:56:46Z")

</div>

The `m` indicates that both nodes are master-eligible. The `*` indicates which one is the currently elected master, of which there will always only be at most one in a cluster.

With a 2 node cluster you should be able to continue reading data (assuming indices has 1 replica shard configured) if one of the nodes fail. With only one node available the cluster will not be able to elect a new master node, which means that writes will fail. In order to have a fully operational cluster in case 1 node fails you need at least 3 master eligible nodes in the cluster.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [February 26, 2020, 7:47am UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/14 "2020-02-26T07:47:45Z")

</div>

> [@nityaraj06](#):
>
> Also could you please let me know how I can test failover conditions with a 2 node cluster

As Christian says, a 2 node cluster does not support failover, so there are no failover conditions to test.

---

<div class="post-metadata">

**Author:** ![mattsdevop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattsdevop/32/45160_2.png) [@mattsdevop](https://discuss.elastic.co/u/mattsdevop)\
**Post date:** [February 27, 2020, 4:21pm UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/15 "2020-02-27T16:21:14Z")

</div>

Yes @DavidTurner. I poorly explained that. Thank you for pointing that out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2020, 4:29pm UTC](https://discuss.elastic.co/t/2-server-elk-cluster-implementation/220308/16 "2020-03-26T16:29:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
