# Best Practice - ES and Kibana on Different Machines?

**URL:** <https://discuss.elastic.co/t/best-practice-es-and-kibana-on-different-machines/19347>\
**Category:** Elasticsearch\
**Created:** [August 19, 2014, 7:01pm UTC](https://discuss.elastic.co/t/best-practice-es-and-kibana-on-different-machines/19347 "2014-08-19T19:01:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrew\_Ruslander](https://avatars.discourse-cdn.com/v4/letter/a/50afbb/32.png) [@Andrew\_Ruslander](https://discuss.elastic.co/u/Andrew_Ruslander)\
**Post date:** [August 19, 2014, 7:01pm UTC](https://discuss.elastic.co/t/best-practice-es-and-kibana-on-different-machines/19347/1 "2014-08-19T19:01:57Z")

</div>

I couldn't find any official documentation or best practices, though it  
seems implied in the Kibana installation instructions, but is there any  
word on whether or not Kibana3 should or should not live on a node in the  
ES cluster? Thoughts on pros and cons of doing so?

Pro - one less box to stand up  
Con - performance impacts on the ES node who drew the short straw?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 19, 2014, 10:10pm UTC](https://discuss.elastic.co/t/best-practice-es-and-kibana-on-different-machines/19347/2 "2014-08-19T22:10:35Z")

</div>

Doesn't really matter as Kibana itself uses very little resources, the  
queries are still going to your cluster. You do need to consider security  
etc though.

You can even run it as an elasticsearch "plugin" if you put it in the  
plugins directory and the access it via $host:9200/\_plugin/kibana.

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 20 August 2014 05:01, Andrew Ruslander [andrew.ruslander@gmail.com](mailto:andrew.ruslander@gmail.com)  
wrote:

> I couldn't find any official documentation or best practices, though it  
> seems implied in the Kibana installation instructions, but is there any  
> word on whether or not Kibana3 should or should not live on a node in the  
> ES cluster? Thoughts on pros and cons of doing so?
> 
> Pro - one less box to stand up  
> Con - performance impacts on the ES node who drew the short straw?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624bFj-CdtAMsavVxygReYf4Q9GcpYcQ7gnFhoyegyqzZHA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624bFj-CdtAMsavVxygReYf4Q9GcpYcQ7gnFhoyegyqzZHA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Andrew\_Ruslander](https://avatars.discourse-cdn.com/v4/letter/a/50afbb/32.png) [@Andrew\_Ruslander](https://discuss.elastic.co/u/Andrew_Ruslander)\
**Post date:** [August 20, 2014, 1:33pm UTC](https://discuss.elastic.co/t/best-practice-es-and-kibana-on-different-machines/19347/3 "2014-08-20T13:33:54Z")

</div>

Thanks for your answer, Mark. What would you recommend as the most secure  
approach? I'm just trying to formulate some sort of argument, however  
minimal, of Kibana on an ES node or not. I am assuming that \*not \*having  
Kibana on the ES node is the more secure setup, as if it were, users would  
be accessing the cluster directly, versus some external box that  
communicates with the ES cluster under controlled ports.

- Andrew

On Tuesday, August 19, 2014 6:11:12 PM UTC-4, Mark Walkom wrote:

> Doesn't really matter as Kibana itself uses very little resources, the  
> queries are still going to your cluster. You do need to consider security  
> etc though.
> 
> You can even run it as an elasticsearch "plugin" if you put it in the  
> plugins directory and the access it via $host:9200/\_plugin/kibana.
> 
> Regards,  
> Mark Walkom
> 
> Infrastructure Engineer  
> Campaign Monitor  
> email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com) \<javascript:\>  
> web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> 
> On 20 August 2014 05:01, Andrew Ruslander \<[andrew.r...@gmail.com](mailto:andrew.r...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > I couldn't find any official documentation or best practices, though it  
> > seems implied in the Kibana installation instructions, but is there any  
> > word on whether or not Kibana3 should or should not live on a node in the  
> > ES cluster? Thoughts on pros and cons of doing so?
> > 
> > Pro - one less box to stand up  
> > Con - performance impacts on the ES node who drew the short straw?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/9dceeb30-3f76-46c8-ac83-e8f3fbeddf7a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9dceeb30-3f76-46c8-ac83-e8f3fbeddf7a%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 20, 2014, 9:27pm UTC](https://discuss.elastic.co/t/best-practice-es-and-kibana-on-different-machines/19347/4 "2014-08-20T21:27:18Z")

</div>

Exactly. It's ultimately up to your own security requirements.

We run separate as we have a web server that runs a few instances of kibana  
and a few other things, which allows finer grained access controls.

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 20 August 2014 23:33, Andrew Ruslander [andrew.ruslander@gmail.com](mailto:andrew.ruslander@gmail.com)  
wrote:

> Thanks for your answer, Mark. What would you recommend as the most secure  
> approach? I'm just trying to formulate some sort of argument, however  
> minimal, of Kibana on an ES node or not. I am assuming that \*not \*having  
> Kibana on the ES node is the more secure setup, as if it were, users would  
> be accessing the cluster directly, versus some external box that  
> communicates with the ES cluster under controlled ports.
> 
> - Andrew
> 
> On Tuesday, August 19, 2014 6:11:12 PM UTC-4, Mark Walkom wrote:
> 
> > Doesn't really matter as Kibana itself uses very little resources, the  
> > queries are still going to your cluster. You do need to consider security  
> > etc though.
> > 
> > You can even run it as an elasticsearch "plugin" if you put it in the  
> > plugins directory and the access it via $host:9200/\_plugin/kibana.
> > 
> > Regards,  
> > Mark Walkom
> > 
> > Infrastructure Engineer  
> > Campaign Monitor  
> > email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com)  
> > web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> > 
> > On 20 August 2014 05:01, Andrew Ruslander [andrew.r...@gmail.com](mailto:andrew.r...@gmail.com) wrote:
> > 
> > > I couldn't find any official documentation or best practices, though it  
> > > seems implied in the Kibana installation instructions, but is there any  
> > > word on whether or not Kibana3 should or should not live on a node in the  
> > > ES cluster? Thoughts on pros and cons of doing so?
> > > 
> > > Pro - one less box to stand up  
> > > Con - performance impacts on the ES node who drew the short straw?
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%  
> > > [40googlegroups.com](http://40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/9d8c5951-8773-4f2f-ac0f-6b54becd6a96%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/9dceeb30-3f76-46c8-ac83-e8f3fbeddf7a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9dceeb30-3f76-46c8-ac83-e8f3fbeddf7a%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/9dceeb30-3f76-46c8-ac83-e8f3fbeddf7a%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/9dceeb30-3f76-46c8-ac83-e8f3fbeddf7a%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624bNb5Ykx%3DnC6JJQCd%3DCjJ09f2QbU8aGCtAA6CpQFaGhcg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624bNb5Ykx%3DnC6JJQCd%3DCjJ09f2QbU8aGCtAA6CpQFaGhcg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:07am UTC](https://discuss.elastic.co/t/best-practice-es-and-kibana-on-different-machines/19347/5 "2017-07-06T01:07:19Z")

</div>


