# Connecting Logstash to Elastic Master or Elastic Data

**URL:** <https://discuss.elastic.co/t/connecting-logstash-to-elastic-master-or-elastic-data/199259>\
**Category:** Elasticsearch\
**Created:** [September 12, 2019, 1:36pm UTC](https://discuss.elastic.co/t/connecting-logstash-to-elastic-master-or-elastic-data/199259 "2019-09-12T13:36:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [September 12, 2019, 1:36pm UTC](https://discuss.elastic.co/t/connecting-logstash-to-elastic-master-or-elastic-data/199259/1 "2019-09-12T13:36:16Z")

</div>

Hello,

When having a Elastic Master servers and Elastic Data servers, should the Logstash consumer point to the Elastic Data for the output or the Elastic Master? What is the difference between the two connections/outputs and which one is recommended?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 13, 2019, 5:43am UTC](https://discuss.elastic.co/t/connecting-logstash-to-elastic-master-or-elastic-data/199259/2 "2019-09-13T05:43:51Z")

</div>

If you have dedicated master nodes in the cluster these should be left to manage the cluster and you should point Logstash to just the data nodes. The whole point of having dedicated mater nodes is to avoid them getting overloaded or have a lot of GC, and the best way to do this is to not send requests to them.

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [September 23, 2019, 8:10pm UTC](https://discuss.elastic.co/t/connecting-logstash-to-elastic-master-or-elastic-data/199259/3 "2019-09-23T20:10:42Z")

</div>

I have setup the logstash to point to the data nodes. All the data is getting replicated across all 3 data nodes. Is this normal behavior? Shouldn't the data be split across all 3 data nodes? The elasticsearch.yml for the data nodes has the following fields added to it:

- cluster name: cluster1
- node.name: ${HOSTNAME}
- node.master: false
- node.data: true
- discovery.zen.ping.unicast.hosts: ["master1", "mastereligible1", "mastereligible2"]
- discovery.zen.minimum\_master\_nodes: 1

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2019, 8:19pm UTC](https://discuss.elastic.co/t/connecting-logstash-to-elastic-master-or-elastic-data/199259/4 "2019-10-21T20:19:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
