# Convert 2 Node Cluster Into Single Node

**URL:** <https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555>\
**Category:** Elasticsearch\
**Created:** [October 13, 2022, 3:54pm UTC](https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555 "2022-10-13T15:54:06Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![rhailey](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@rhailey](https://discuss.elastic.co/u/rhailey)\
**Post date:** [October 13, 2022, 3:54pm UTC](https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555/1 "2022-10-13T15:54:06Z")

</div>

Hello -  
I'm currently using Elastic 7.11 (open/communitiy version) as the back-end storage for Graylog (also the open/community version). OS is Oracle Linux v8.

I have 2 Graylog servers, clustered, in front of 2 Elastic servers, clustered. All of this is sitting behind a load balancer.

I have a need to, effectively, break the clustering so that I only have one Graylog and one Elastic server. The Graylog part is easy enough. My concerns are around breaking the Elastic cluster and ensuring that I don't lose any of our log data in the process.

We don't really manage (for lack of a better term) Elastic - it's mostly just sitting there collecting/storing log data. So, my Elastic skills are pretty sparse. I've been trying to search for information about the process needed to make this change but, I'm coming up a bit short on helpful items (at least for someone with my level of comfort with Elasticsearch).

Anyway, does anyone have handy a good resource for changing a 2 node cluster into a single node? Whether it's something official from Elastic or something you've put together previously that you don't mind sharing.

Thanks for any help or pointers you can provide.

Robin

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 14, 2022, 4:25am UTC](https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555/2 "2022-10-14T04:25:50Z")

</div>

Welcome to our community! 😃

You can do this, but be aware if you lose the node you lose your data (unless you have a backup). The easiest way is to use an [allocation filter](https://www.elastic.co/guide/en/elasticsearch/reference/8.4/modules-cluster.html#cluster-shard-allocation-filtering) to exclude allocation to one of the nodes, then once it is "empty" shut it down, and then disable replicas.

---

<div class="post-metadata">

**Author:** ![rhailey](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@rhailey](https://discuss.elastic.co/u/rhailey)\
**Post date:** [October 14, 2022, 1:00pm UTC](https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555/3 "2022-10-14T13:00:46Z")

</div>

Thanks Mark. That's very helpful.  
I do have some follow up questions if you don't mind.

Presumably, I'd run/create that allocation filter on the node that I'm planning to keep, right?  
You mentioned waiting for the node to become 'empty' - is there a command I can use to verify that has occurred?  
Then, once the second node is shutdown, is there any need to remove that filter? I'm guessing it probably doesn't matter at that point.

Lastly, in the elasticsearch.yml file on the remaining node, I would want to update the items  
discovery.seed\_hosts and cluster.initial\_master\_nodes to remove the excluded node - correct? What about cluster.name - can/do I just leave that as is or comment it out?

Thanks again for your help.  
Robin

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 16, 2022, 10:26pm UTC](https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555/4 "2022-10-16T22:26:34Z")

</div>

> [@rhailey](#):
>
> Presumably, I'd run/create that allocation filter on the node that I'm planning to keep, right?

It doesn't matter which node you make the request to.

> [@rhailey](#):
>
> You mentioned waiting for the node to become 'empty' - is there a command I can use to verify that has occurred?

`_cat/allocation` is easiest.

> [@rhailey](#):
>
> Then, once the second node is shutdown, is there any need to remove that filter? I'm guessing it probably doesn't matter at that point.

Replace the IP with `""` and it'll remove it.

> [@rhailey](#):
>
> I would want to update the items  
> discovery.seed\_hosts and cluster.initial\_master\_nodes to remove the excluded node - correct?

Yes.

> [@rhailey](#):
>
> What about cluster.name - can/do I just leave that as is or comment it out?

I wouldn't change that.

---

<div class="post-metadata">

**Author:** ![rhailey](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@rhailey](https://discuss.elastic.co/u/rhailey)\
**Post date:** [October 18, 2022, 12:59pm UTC](https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555/5 "2022-10-18T12:59:13Z")

</div>

Thanks Mark.

That seemed to be working until the node I was planning to keep ran out of disk space so, I ended up removing the filter and letting it re-populate the other node.

To that point, maybe I’ve misunderstood how the Elastic cluster works. On each of my 2 nodes, I’ve got a little over 500gb of data. Does that mean I have a total of 1TB of Elastic data?

The assumption we had was we had a total of 500GB of Elastic data that was replicated across the 2 nodes. And when they were combined, we’d end up with roughly 500gb of data. Seems that may not be the case or, is there some process that hadn’t run to merge/dedupe the data because of the space issues?

Robin

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 19, 2022, 3:08am UTC](https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555/6 "2022-10-19T03:08:07Z")

</div>

If you have every index replicated, then your total store size will include both primary and replicas, yes.

Did you remove the replicas before setting the filter?

---

<div class="post-metadata">

**Author:** ![rhailey](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@rhailey](https://discuss.elastic.co/u/rhailey)\
**Post date:** [October 19, 2022, 1:01pm UTC](https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555/7 "2022-10-19T13:01:53Z")

</div>

No, I didn’t remove any replicas (didn’t realize that was needed).

Would that be doing something like this:

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 19, 2022, 1:10pm UTC](https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555/8 "2022-10-19T13:10:27Z")

</div>

In addition to relocating shards and eliminating replicas you probably need to manually [remove one of the master eligible nodes from the voting configuration before removing it](https://www.elastic.co/guide/en/elasticsearch/reference/8.4/add-elasticsearch-nodes.html#modules-discovery-removing-nodes). If you just shut it down I suspect the cluster will go red and not function properly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2022, 1:11pm UTC](https://discuss.elastic.co/t/convert-2-node-cluster-into-single-node/316555/9 "2022-11-16T13:11:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
