# Cluster with packetbeat

**URL:** https://discuss.elastic.co/t/cluster-with-packetbeat/330929
**Category:** Beats
**Tags:** packetbeat
**Created:** [April 27, 2023, 9:08am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929 "2023-04-27T09:08:54Z")
**Posts on this page:** 18
**Page:** 1

<div class="post-metadata">

### Author: ![elastic\_user4](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)
#### Post date: [April 27, 2023, 9:08am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/1 "2023-04-27T09:08:54Z")

</div>

Hello, I'm trying to form a cluster and in this cluster I want to add several nodes and install packtbeat on each node. But when I do that, the data sent from packtbeat is shared across the entire cluster. Is there any way to send data to the node where packtbeat is installed? Or filter the data? And what would be the best structure for this problem?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [April 30, 2023, 11:14pm UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/2 "2023-04-30T23:14:04Z")

</div>

Welcome to our community! 😃

> [@elastic\_user4](#):
>
> Is there any way to send data to the node where packtbeat is installed

You can tell Packetbeat to only ingest the data it gets to a single node, but if that node is part of the cluster then the indices will be shared across all the nodes. That's what Elasticsearch is designed to do.

> [@elastic\_user4](#):
>
> And what would be the best structure for this problem?

It's not clear what the problem you are trying to solve is sorry 🙂

---

<div class="post-metadata">

### Author: ![elastic\_user4](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)
#### Post date: [May 2, 2023, 9:29am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/3 "2023-05-02T09:29:41Z")

</div>

And if I have 2 clusters and then apply cross-clustering, would I be able to analyze the data without it being replicated?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 2, 2023, 9:30am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/4 "2023-05-02T09:30:52Z")

</div>

> [@elastic\_user4](#):
>
> then apply cross-clustering

Cross cluster what - search or replication?

---

<div class="post-metadata">

### Author: ![elastic\_user4](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)
#### Post date: [May 2, 2023, 9:33am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/5 "2023-05-02T09:33:13Z")

</div>

Sorry, yes search or replication

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 2, 2023, 9:34am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/6 "2023-05-02T09:34:30Z")

</div>

Yes you shoudl be able to do that without having to replicate that across each cluster, unless you actually use cross cluster replication that is.

---

<div class="post-metadata">

### Author: ![elastic\_user4](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)
#### Post date: [May 2, 2023, 9:35am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/7 "2023-05-02T09:35:26Z")

</div>

Ok so if I have 2 clusters can I do cross search and analyze the data from these 2 clusters without replicating?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 2, 2023, 9:37am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/8 "2023-05-02T09:37:42Z")

</div>

Based on what you have told us here, yes that should work.

---

<div class="post-metadata">

### Author: ![elastic\_user4](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)
#### Post date: [May 2, 2023, 9:52am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/9 "2023-05-02T09:52:59Z")

</div>

In this document ([Trust management | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-trust-management.html#ec-trust-self-managed)) it says that the clusters have to trust each other and to do that I have to go to Trusted deployments \> Add trusted environment, but I don't have this option in my kibana, I'm using your 30 days free-trail.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 2, 2023, 9:56am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/10 "2023-05-02T09:56:08Z")

</div>

You're using our Cloud service?

---

<div class="post-metadata">

### Author: ![elastic\_user4](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)
#### Post date: [May 2, 2023, 9:57am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/11 "2023-05-02T09:57:57Z")

</div>

No, my infrastructure is on-premises

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 2, 2023, 10:05am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/12 "2023-05-02T10:05:02Z")

</div>

That link is for our Elasticsearch Service then, so it doesn't apply.

Try [Cross-cluster replication | Elasticsearch Guide [8.7] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.7/xpack-ccr.html)

---

<div class="post-metadata">

### Author: ![elastic\_user4](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)
#### Post date: [May 2, 2023, 10:07am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/13 "2023-05-02T10:07:14Z")

</div>

This documentation is for cross-cluster replication I don't want that I want cross-cluster search. Can you give the documentation for the cross-cluster search please.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 2, 2023, 10:08am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/14 "2023-05-02T10:08:50Z")

</div>

Sorry it's kind of hard to follow you, as you were talking about replication, then talking about cloud, now you are on prem and want cross cluster search.

Try [Search across clusters | Elasticsearch Guide [8.7] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.7/modules-cross-cluster-search.html).

---

<div class="post-metadata">

### Author: ![elastic\_user4](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)
#### Post date: [May 2, 2023, 10:17am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/15 "2023-05-02T10:17:18Z")

</div>

I tried to do the first step in this documentation([Tutorial: Set up cross-cluster replication | Elasticsearch Guide [8.7] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.7/ccr-getting-started-tutorial.html#_connect_to_a_remote_cluster)) and I couldn't connect one cluster with another i have port 9300 open on both clusters

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 2, 2023, 10:19am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/16 "2023-05-02T10:19:32Z")

</div>

I think it'd be worth creating a new topic for that 🙂

---

<div class="post-metadata">

### Author: ![elastic\_user4](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)
#### Post date: [May 2, 2023, 10:21am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/17 "2023-05-02T10:21:24Z")

</div>

> [@Cross-cluster](https://discuss.elastic.co/t/cross-cluster/332253):
>
> I tried to do the first step in this documentation([Tutorial: Set up cross-cluster replication | Elasticsearch Guide [8.7] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.7/ccr-getting-started-tutorial.html#_connect_to_a_remote_cluster)) and I couldn't connect one cluster with another i have port 9300 open on both clusters.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 30, 2023, 10:21am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929/18 "2023-05-30T10:21:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
