We are going to expand our test cluster with 3 "everything" nodes to split up ingest/master and data roles.
We are mostly a logcluster with winlogbeat and filebeats.
Something like this (sketch from supper table)
I want to split up the filebeat recivers that gets netflow, other cisco logs from the data nodes.
Is this the right way to go, or am I totally off with this way of thinking?
(ignore the connections between ingest and data nodes)