# Changing node roles in an already existing ES environment

**URL:** <https://discuss.elastic.co/t/changing-node-roles-in-an-already-existing-es-environment/307013>\
**Category:** Elasticsearch\
**Created:** [June 13, 2022, 10:06am UTC](https://discuss.elastic.co/t/changing-node-roles-in-an-already-existing-es-environment/307013 "2022-06-13T10:06:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Carlos\_T](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_t/32/97624_2.png) [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Post date:** [June 13, 2022, 10:06am UTC](https://discuss.elastic.co/t/changing-node-roles-in-an-already-existing-es-environment/307013/1 "2022-06-13T10:06:47Z")

</div>

Good morning everybody.

As, due to my job, I will have to get a Production ES environment in the future, I decided to create a testing ES environment at home.

This environment has three multi-role node. The three of them are master nodes, and as I didn't change any of the role option in their respectives Elasticsearch.yml files, I guess that all of them are data nodes aswell, (they all store shards and documents), they all are also cordinatoors and ingest nodes.

I though that this was the best approach as I couldn't count with much RAM and storage, but soon I will have extra hardware resources, so I'm recosidering to convert my three multi-role servers into masternodes dedicated server. I will create also at least a couple of data nodes aswell.

The point here is that I've been using and setting up filebeat and metric beat, which means that I've already uploaded some index templates and created ingesting index to/in those master servers. My indices are rotating on daily basis and they get removed when they are older than seven days. So I guess that once I've got my data dedicated servers the indices will be created in the dataservers as soon as my masterserver stop being dataservers too. Also, after a week, those indices that remained at that point in the dedicated master servers will dissappear.

But there are other indices which purpose are unknown to me and they make me worry.

If I go to Kibana -\> Index Management I can find the following indices:  
_.items-default-000001_  
_.lists-default-000001_  
metrics-endpoint.metadata\_current\_default

The following 'Data Streams':  
_filebeat-8.2.1_  
_metricbeat-8.2.1_

The following 'Index templates':  
_ecs-logstash_  
_filebeat-8.2.1_  
_ilm-history_  
_logs_  
_logs-endpoint.alerts_  
_logs-endpoint.events.file_  
_logs-endpoint.events.library_  
_logs-endpoint.events.network_  
_logs-endpoint.events.process_  
_logs-endpoint.events.registry_  
_logs-endpoint.events.security_  
_metricbeat-8.2.1_  
_metrics_  
_metrics-endpoint.metadata_  
_metrics-endpoint.metrics_  
_metrics-endpoint.policy_  
_metrics-metadata-current_  
_metrics-metadata-united_  
_synthetics_

And also a good number of Component templates.

So that are my goals. Could please someone advise me about what should I have into consideration?. I'm sure I'm missing key things.

Thank you in advance.

Carlos T.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 14, 2022, 11:15pm UTC](https://discuss.elastic.co/t/changing-node-roles-in-an-already-existing-es-environment/307013/2 "2022-06-14T23:15:21Z")

</div>

> [@Carlos\_T](#):
>
> So I guess that once I've got my data dedicated servers the indices will be created in the dataservers as soon as my masterserver stop being dataservers too. Also, after a week, those indices that remained at that point in the dedicated master servers will dissappear.

Nodes, not servers, but yes that summary is correct.

> [@Carlos\_T](#):
>
> But there are other indices which purpose are unknown to me and they make me worry.

These are system configs and indices, you don't need to worry about them as they are automatically managed.

---

<div class="post-metadata">

**Author:** ![Carlos\_T](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_t/32/97624_2.png) [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Post date:** [June 16, 2022, 8:39am UTC](https://discuss.elastic.co/t/changing-node-roles-in-an-already-existing-es-environment/307013/3 "2022-06-16T08:39:05Z")

</div>

Thank you very much Warkolm.

I've already included two datanodes. From the very beginning ES started to move shards from the three masternodes to the datanodes. Now I have changed ILM settings so the older indices get removed.

I don't have much time now for my home environment, but I intend to remove the datanode role gradually (one by one) from the three masternodes. So far everything is going as you said.

So thank you again and long life to the dark side of the force.

---

<div class="post-metadata">

**Author:** ![Carlos\_T](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_t/32/97624_2.png) [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Post date:** [June 24, 2022, 6:17pm UTC](https://discuss.elastic.co/t/changing-node-roles-in-an-already-existing-es-environment/307013/4 "2022-06-24T18:17:10Z")

</div>

So. Finally I took the time for investigating and trying to progress.  
After applying ILM my beats indices dissapaired from the multirole nodes and started to get created in the datanodes. At that point I've reconfigured the three multiroles nodes to be just masternodes:

> node.roles: [master]

At that point the environment failed when I tried to start it reporting that a node that contains shards can't stop being a datanode. And the thing is that beat indices are just a part of the whole index set.  
So what I've done is transfering the rest of shards from my multirole nodes with IP's: 111, 112 and 113 to my Datanodes with IP's 115 and 116

So I went to the 'Dev Tools' console and run:

**PUT \_cluster/settings**

**{**

**"persistent" : {**

**"cluster.routing.allocation.require.\_ip" : ["192.168.0.115", "192.168.0.116"]**

**}**

**}**

**PUT \_cluster/settings**

**{**

**"persistent" : {**

**"cluster.routing.allocation.exclude.\_ip" : ["192.168.0.111", "192.168.0.112","192.168.0.113"]**

**}**

**}**

Some minutes later 100% of indices had moved into the datanodes. Not just the beat's ones like before.

And since I did that I could change the multirole nodes into simply masternodes.  
I restarted the 5 nodes and everything seems to work fine. Dashboards, HA, ingestions, etc...

Thanks all for your help.

Carlos T.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2022, 6:17pm UTC](https://discuss.elastic.co/t/changing-node-roles-in-an-already-existing-es-environment/307013/5 "2022-07-22T18:17:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
