# Architecture of elasticsearch-xpack monitoring with Metricbeat

**URL:** <https://discuss.elastic.co/t/architecture-of-elasticsearch-xpack-monitoring-with-metricbeat/274168>\
**Category:** Beats\
**Tags:** elastic-stack-monitoring, metricbeat\
**Created:** [May 27, 2021, 9:19am UTC](https://discuss.elastic.co/t/architecture-of-elasticsearch-xpack-monitoring-with-metricbeat/274168 "2021-05-27T09:19:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kodka](https://avatars.discourse-cdn.com/v4/letter/k/da6949/32.png) [@kodka](https://discuss.elastic.co/u/kodka)\
**Post date:** [May 27, 2021, 9:19am UTC](https://discuss.elastic.co/t/architecture-of-elasticsearch-xpack-monitoring-with-metricbeat/274168/1 "2021-05-27T09:19:22Z")

</div>

Documentation ([Collecting Elasticsearch monitoring data with Metricbeat | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-metricbeat.html)) says: "Ideally install a single Metricbeat instance configured with scope: cluster and configure hosts to point to an endpoint (e.g. a load-balancing proxy) which directs requests to the master-ineligible nodes in the cluster."

But if i have only 1 metricbeat configured, there is single point of failure, and if i have metricbeat on the other master-eligible nodes as well with scope: cluster, they are collecting the same data and producing triple the amount of logs.

What is the best configuration for a large production cluster? I tried to have metricbeat to each node with scope: node, but it's not even working well (data comes from time to time on big chunks).

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [May 28, 2021, 9:15am UTC](https://discuss.elastic.co/t/architecture-of-elasticsearch-xpack-monitoring-with-metricbeat/274168/2 "2021-05-28T09:15:21Z")

</div>

> What is the best configuration for a large production cluster? I tried to have metricbeat to each node with scope: node, but it's not even working well (data comes from time to time on big chunks).

You can configure delivery periods and size of chunks (I think).

---

<div class="post-metadata">

**Author:** ![kodka](https://avatars.discourse-cdn.com/v4/letter/k/da6949/32.png) [@kodka](https://discuss.elastic.co/u/kodka)\
**Post date:** [May 31, 2021, 8:03am UTC](https://discuss.elastic.co/t/architecture-of-elasticsearch-xpack-monitoring-with-metricbeat/274168/3 "2021-05-31T08:03:24Z")

</div>

Thank you for your reply!  
Yes, there are period settings, but if you make it more than 10 secs, data starts to appear as dots instead of chart.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2021, 10:04am UTC](https://discuss.elastic.co/t/architecture-of-elasticsearch-xpack-monitoring-with-metricbeat/274168/4 "2021-06-28T10:04:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
