# Connect to elasticsearch cluster

**URL:** <https://discuss.elastic.co/t/connect-to-elasticsearch-cluster/312684>\
**Category:** Elasticsearch\
**Created:** [August 23, 2022, 8:26am UTC](https://discuss.elastic.co/t/connect-to-elasticsearch-cluster/312684 "2022-08-23T08:26:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![skyle52](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skyle52/32/105821_2.png) [@skyle52](https://discuss.elastic.co/u/skyle52)\
**Post date:** [August 23, 2022, 8:26am UTC](https://discuss.elastic.co/t/connect-to-elasticsearch-cluster/312684/1 "2022-08-23T08:26:35Z")

</div>

Hello all,  
I have a question about elasticsearch cluster, please advise:  
I setup 3 nodes elasticsearch cluster with each node have all the default roles. But I don't know how my filebeat or logstash can push log to elasticsearch cluster and distribute index across 3 nodes. I have read on a forum that I need a "coordinating node" for routing purpose. However, on the elasticsearch guide, "Coordinating only nodes can benefit large clusters....", but I have only 3 nodes on my cluster.  
So my question is, do I must setup a coordinate node for my cluster? If not, how can I push log from filebeat to all elasticsearch nodes?

Thanks for helping!

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/e/ae3b55dd1a024adaf69be87d2cbdd993e2a43de6.png)

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [August 23, 2022, 9:03am UTC](https://discuss.elastic.co/t/connect-to-elasticsearch-cluster/312684/2 "2022-08-23T09:03:37Z")

</div>

Hello!  
I've got three nodes in one of my clusters.  
All nodes have:

- elasticsearch
- kibana
- logstash
- filebeat

In my elasticsearch.yml i set all nodes as master and data.

```auto
node.master: true
node.data: true

```

and in filebeat configuration - /etc/filebeat/filebeat.yml I have got:

```auto
output.logstash:
  # The Logstash hosts
   hosts: ["111.111.1111.111:5000", "222.222.222.222:5000", "333.333.333.333:5000"]

```

of course in my conf file there are real IPs ans PORTs (that I don't want to show 🙂 ).

The other thing is that you can have more than one input for logstash per node - you have to create more config files:

```auto
# ls -la /etc/logstash/conf.d/
razem 16
drwxr-xr-x 2 root root 4096 08-08 14:13 .
drwxr-xr-x 3 root root 4096 08-16 11:39 ..
-rw-r--r-- 1 root root 1161 07-27 09:14 filebeat.conf
-rw-r--r-- 1 root root 1116 07-27 14:21 metricbeat.conf

```

---

<div class="post-metadata">

**Author:** ![skyle52](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skyle52/32/105821_2.png) [@skyle52](https://discuss.elastic.co/u/skyle52)\
**Post date:** [August 24, 2022, 3:33am UTC](https://discuss.elastic.co/t/connect-to-elasticsearch-cluster/312684/3 "2022-08-24T03:33:07Z")

</div>

Thanks for your idea, i will try that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2022, 3:33am UTC](https://discuss.elastic.co/t/connect-to-elasticsearch-cluster/312684/4 "2022-09-21T03:33:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
