# Best practice for a logging cluster

**URL:** <https://discuss.elastic.co/t/best-practice-for-a-logging-cluster/37360>\
**Category:** Elasticsearch\
**Created:** [December 16, 2015, 2:22pm UTC](https://discuss.elastic.co/t/best-practice-for-a-logging-cluster/37360 "2015-12-16T14:22:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![elvarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elvarb/32/44840_2.png) [@elvarb](https://discuss.elastic.co/u/elvarb)\
**Post date:** [December 16, 2015, 2:22pm UTC](https://discuss.elastic.co/t/best-practice-for-a-logging-cluster/37360/1 "2015-12-16T14:22:49Z")

</div>

I'm setting up a new logging cluster consisting of 3x dedicated master nodes, 6x dedicated data nodes and 1-2x client nodes to handle Kibana requests.

Now I'm wondering what is the best practice of ingesting data from Logstash. Up until now I have had an client instance of Elasticsearch on the Logstash indexing nodes and it has been going ok, but not great during cluster load.

The methods I have come up with are

- Continue with one elasticsearch client node instance per indexing computer
- Have dedicated client nodes that Logstash sends to
- Share the client node that will be used for Kibana with Logstash (totally different function so it might affect memory usage)
- Have Logstash send to all 6x data nodes, no client nodes for Logstash

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 17, 2015, 3:34am UTC](https://discuss.elastic.co/t/best-practice-for-a-logging-cluster/37360/2 "2015-12-17T03:34:11Z")

</div>

In this case there is no real best practise, it's what works for you .

---

<div class="post-metadata">

**Author:** ![elvarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elvarb/32/44840_2.png) [@elvarb](https://discuss.elastic.co/u/elvarb)\
**Post date:** [December 17, 2015, 9:55am UTC](https://discuss.elastic.co/t/best-practice-for-a-logging-cluster/37360/3 "2015-12-17T09:55:51Z")

</div>

Trial and error here I come 🙂

Going to start with sharing the client nodes with Kibana, easiest to start with and the lowest risk

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 18, 2015, 9:13am UTC](https://discuss.elastic.co/t/best-practice-for-a-logging-cluster/37360/4 "2015-12-18T09:13:16Z")

</div>

Yep, that's definitely the best place to start!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:30pm UTC](https://discuss.elastic.co/t/best-practice-for-a-logging-cluster/37360/5 "2017-07-05T23:30:00Z")

</div>


