# Central Elastic Stack setup for a company with 10+ applications using Elasticsearch

**URL:** <https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800>\
**Category:** Elasticsearch\
**Created:** [April 12, 2023, 6:18am UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800 "2023-04-12T06:18:07Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![murat3](https://avatars.discourse-cdn.com/v4/letter/m/e274bd/32.png) [@murat3](https://discuss.elastic.co/u/murat3)\
**Post date:** [April 12, 2023, 6:18am UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800/1 "2023-04-12T06:18:07Z")

</div>

Hello all,

I am trying to understand the setup of a (central) Elastic Stack cluster used by 10+ projects and 20+ applications. Our applications consist of frontend web and Java backend applications.

One Cluster  
Is one central cluster (with multiple nodes) sufficient?  
Managability:

- not in terms of hardware capacity but;
- ease of making changes to the cluster (configuration) without disturbing other users
- data encapsulation (protection); some indices only visible for owners
- managing pipelines
- managing security

Multiple Clusters  
Or should you have multiple clusters; one for each project?  
If multiple clusters, how about sharing data (indices / log events) between 2 clusters?  
is it possible to share indices in realtime? How does Elastic Stack support this?

Thanks in advance!

Murat

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [April 13, 2023, 11:46am UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800/2 "2023-04-13T11:46:05Z")

</div>

Hello Murat,

I think your best option is to build multiple clusters. Data encapsulation and security is not a big thing and can be done on a single stack too ([Document Level Security](https://www.elastic.co/guide/en/elasticsearch/reference/current/document-level-security.html) allows filtering data on a per-role basis, [Field Level Security](https://www.elastic.co/guide/en/elasticsearch/reference/current/field-level-security.html) allows hiding sensitive fields on a per-role basis).  
The main benefits for you are:

1. You can update the clusters independently from each other
2. some features(e.g. managing pipelines) require stack admin privileges. With multiple stacks the team can get those privileges on their own stack.

Data can be shared between the clusters in different ways:

- [Cross Cluster Search](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-cross-cluster-search.html) allows searching in remote clusters. As you search directly in the remote cluster the data is always up to date
- [Cross Cluster Replication](https://www.elastic.co/guide/en/elasticsearch/reference/current/xpack-ccr.html) copies the data from a single cluster to one or more other clusters. The search will only execute on your local cluster but you can only see the data that was already replicated.

There may be more options but this can give you a first overview.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 13, 2023, 12:46pm UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800/3 "2023-04-13T12:46:35Z")

</div>

> [@murat3](#):
>
> ease of making changes to the cluster (configuration) without disturbing other users

This is pretty broad and depend on the changes, do you have any example? Some changes you can do without disturbing the users, other changes you may need to restart the cluster which can disturb of the user, it is pretty hard to answer without an example of what kind of changes you are referring to.

> [@murat3](#):
>
> data encapsulation (protection); some indices only visible for owners

Can be done pretty easily with roles and setting a naming convention for the indices, as mentioned you also have Document and Field level security, but those are paid features, with the Basic and free license you only have index level security.

> [@murat3](#):
>
> managing pipelines

What kind of pipelines? Ingest pipelines? Pretty easy to manage as well, you have APIs or can do in Kibana UI.

> [@murat3](#):
>
> managing security

Also, no issues, APIs and Kibana UI.

Would help if you provided more context what you want to achieve.

---

<div class="post-metadata">

**Author:** ![murat3](https://avatars.discourse-cdn.com/v4/letter/m/e274bd/32.png) [@murat3](https://discuss.elastic.co/u/murat3)\
**Post date:** [April 14, 2023, 9:22pm UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800/4 "2023-04-14T21:22:00Z")

</div>

Hello @leandrojmp

As I understand now from your and Wolfram's reply data encapsulation is not a problem. This can be arranged fairly easy with Role based security.

I am new into the Elastic Stack and just want to know what the intended way of usage is for a big company. Because in theory you can just work with one cluster if data ingestion is fairly generic for all projects/users.

At our company we make use of PaaS Cloud platform which provides all its users with a standard infrastructure, a Java Application Server and Database. Filebeat comes pre-installed on each cloud instance. Log files (infra + application logs) from all Cloud instances are sent to the same Kafka topic. Each log event gets tagged with a project specific field.

What about managing Logstash pipelines in this specific situation?  
Can you have separate Logstash pipelines for each project/application/log event type?  
Working with just one pipeline for 10+ users (projects) will be very difficult I guess.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [April 15, 2023, 1:25am UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800/5 "2023-04-15T01:25:54Z")

</div>

What licensing level are your using? If free, you need different stacks. If you're paying for licenses, a stack per app will probably be expensive. As others have said, RBAC will provide the security you need for multi tenant stacks.

---

<div class="post-metadata">

**Author:** ![murat3](https://avatars.discourse-cdn.com/v4/letter/m/e274bd/32.png) [@murat3](https://discuss.elastic.co/u/murat3)\
**Post date:** [April 18, 2023, 3:01pm UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800/6 "2023-04-18T15:01:35Z")

</div>

@rugenl

We have a payed subscription (which license level I don't know).

Is it also possible to manage who can create/read/edit specific Logstash pipelines with RBAC?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 18, 2023, 10:33pm UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800/7 "2023-04-18T22:33:12Z")

</div>

> [@murat3](#):
>
> We have a payed subscription (which license level I don't know).

You should be reaching out to your support contact then, they can definitely provide advice here.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [April 19, 2023, 5:03pm UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800/8 "2023-04-19T17:03:57Z")

</div>

Yes, use a limited account for the logstash connection, I suggest different accounts for "writers" vs "readers" anyway. If you move to the beats/agents using ILM and streams, they need rights to define templates and indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2023, 5:04pm UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800/9 "2023-05-17T17:04:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
