# Can you answer these ELK questions?

**URL:** <https://discuss.elastic.co/t/can-you-answer-these-elk-questions/243047>\
**Category:** Elasticsearch\
**Created:** [July 29, 2020, 11:59am UTC](https://discuss.elastic.co/t/can-you-answer-these-elk-questions/243047 "2020-07-29T11:59:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![myrsecurity](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@myrsecurity](https://discuss.elastic.co/u/myrsecurity)\
**Post date:** [July 29, 2020, 11:59am UTC](https://discuss.elastic.co/t/can-you-answer-these-elk-questions/243047/1 "2020-07-29T11:59:11Z")

</div>

Given the following use case:  
Filebeat and Metricbeat installed on 10 centos. Each centos location represents a different customer (tenant):

Topology and authentication

Can we authenticate each feed and make sure that each connection is identified and tied back to a tenant ?  
In an ideal world they all talk back to a single connection point in the cloud. Let's say it's something like this...  
i. DNS Name: [Telemetry.mysecure.com](http://Telemetry.mysecure.com)  
ii. PORT: 443  
Does each device register with the system and identify itself so we can track its information independently?  
I guess, each Customer will register with a separate node (=tenant), correct?  
Does Elastic Search make sure one device can't impersonate another and hijack their data slot?  
Does Elastic Search make sure one device cant contaminate another's data feed, that would be bad?

Infrastructure  
Can we host multiple customers with multiple systems on a single node?  
Or is one node dedicated to one Customer with multiple systems?  
Is TLS encryption included, in case we buy 3 or more nodes per year?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 29, 2020, 12:57pm UTC](https://discuss.elastic.co/t/can-you-answer-these-elk-questions/243047/2 "2020-07-29T12:57:21Z")

</div>

Some answers depend on what license level you use, I'll assume at least Gold.

> [@myrsecurity](#):
>
> Can we authenticate each feed and make sure that each connection is identified and tied back to a tenant ?

Yes, for example [API keys](https://www.elastic.co/guide/en/beats/filebeat/current/beats-api-keys.html)

> [@](#):
>
> In an ideal world they all talk back to a single connection point in the cloud. Let's say it's something like this...  
> i. DNS Name: [Telemetry.mysecure.com](http://Telemetry.mysecure.com)  
> ii. PORT: 443  
> Does each device register with the system and identify itself so we can track its information independently?

I'm not sure what you are asking. Assuming you authenticate each feed with a unique user account, then the security would be controlled as to what indices they could read and write. The monitoring interface could be configured to include the beats from each feed.

However, it's sometimes better to use a common index for like data, in the case of common indices, the agent.hostname would be unique for each sending host.

> [@](#):
>
> I guess, each Customer will register with a separate node (=tenant), correct?  
> Does Elastic Search make sure one device can't impersonate another and hijack their data slot?  
> Does Elastic Search make sure one device cant contaminate another's data feed, that would be bad?

Control this with unique account security.

> [@](#):
>
> Infrastructure  
> Can we host multiple customers with multiple systems on a single node?  
> Or is one node dedicated to one Customer with multiple systems?  
> Is TLS encryption included, in case we buy 3 or more nodes per year?

Elasticsearch is best as a multi node redundant service. Maybe [this will help.](https://www.elastic.co/blog/found-multi-tenancy)

TLS is included and recommended. There is a setup for node-to-node communication and a seperate setup for client communication. If you add nodes, you need to add them to the certificates for node-to-node communication.

---

<div class="post-metadata">

**Author:** ![myrsecurity](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@myrsecurity](https://discuss.elastic.co/u/myrsecurity)\
**Post date:** [July 30, 2020, 7:34am UTC](https://discuss.elastic.co/t/can-you-answer-these-elk-questions/243047/3 "2020-07-30T07:34:55Z")

</div>

thanks Len this helps, we will come back as soon as we digest this info

---

<div class="post-metadata">

**Author:** ![myrsecurity](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@myrsecurity](https://discuss.elastic.co/u/myrsecurity)\
**Post date:** [July 30, 2020, 3:17pm UTC](https://discuss.elastic.co/t/can-you-answer-these-elk-questions/243047/4 "2020-07-30T15:17:24Z")

</div>

By the way, could you also help us answering these 2 questions?

| a. | Can we host multiple customers with multiple systems on a single node? |
| --- | --- |
| b. | Or is one node dedicated to one Customer with multiple systems? |

I would say that each customer data could be aggregated into dedicated index within a shard?

Thanks

---

<div class="post-metadata">

**Author:** ![myrsecurity](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@myrsecurity](https://discuss.elastic.co/u/myrsecurity)\
**Post date:** [July 30, 2020, 3:22pm UTC](https://discuss.elastic.co/t/can-you-answer-these-elk-questions/243047/5 "2020-07-30T15:22:32Z")

</div>

Additional questions:

1. Can we route the comms via our DNS namespace?

2. For example: **[cOMMS.mysecure.com:443](http://cOMMS.mysecure.com:443)**

3. How many nodes are required for 10-12 of our Customers (segregated by unique API key), each having between 2-10 Filebeat and Metricbeat Agents installed on Linux servers?

Cheers, thanks in advance

---

<div class="post-metadata">

**Author:** ![myrsecurity](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@myrsecurity](https://discuss.elastic.co/u/myrsecurity)\
**Post date:** [July 30, 2020, 3:38pm UTC](https://discuss.elastic.co/t/can-you-answer-these-elk-questions/243047/6 "2020-07-30T15:38:40Z")

</div>

I understand that:  
Each customer devices would share a unique API key –feeds coming from the same API key (whether 1 or 20 devices ) can be aggregated in a) the main index or b) dedicated customer specific index or c) both  
Feeds are TLS encrypted end to end.  
Feeds can talk to the same DNS hostname: [COMMS.mysecure.com:443](http://COMMS.mysecure.com:443) behind this DNS hostname the Logstash component identity API keys, filter and forward to Elastic index/indexes  
Nodes depend on amount of data – possibly Elastic have a Sizing document to help calculate this

accurate?

accurate?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2020, 3:38pm UTC](https://discuss.elastic.co/t/can-you-answer-these-elk-questions/243047/7 "2020-08-27T15:38:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
