# Creating "prod" cluster with ingest nodes?

**URL:** <https://discuss.elastic.co/t/creating-prod-cluster-with-ingest-nodes/247007>\
**Category:** Elasticsearch\
**Created:** [August 31, 2020, 7:23pm UTC](https://discuss.elastic.co/t/creating-prod-cluster-with-ingest-nodes/247007 "2020-08-31T19:23:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andreas\_Falk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas_falk/32/82595_2.png) [@Andreas\_Falk](https://discuss.elastic.co/u/Andreas_Falk)\
**Post date:** [August 31, 2020, 7:23pm UTC](https://discuss.elastic.co/t/creating-prod-cluster-with-ingest-nodes/247007/1 "2020-08-31T19:23:34Z")

</div>

Hi,

We are going to expand our test cluster with 3 "everything" nodes to split up ingest/master and data roles.  
We are mostly a logcluster with winlogbeat and filebeats.

Something like this (sketch from supper table) 🙂  
I want to split up the filebeat recivers that gets netflow, other cisco logs from the data nodes.

Is this the right way to go, or am I totally off with this way of thinking?

 ![photo_2020-08-31_21-03-50](https://us1.discourse-cdn.com/elastic/original/3X/6/9/696f50fc234f4793b07a8b12afdefeba89a94867.jpeg)

(ignore the connections between ingest and data nodes) 😃

--  
Regards Falk

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 31, 2020, 9:36pm UTC](https://discuss.elastic.co/t/creating-prod-cluster-with-ingest-nodes/247007/2 "2020-08-31T21:36:02Z")

</div>

It makes sense. The only issue with this is that if your ingest loads put too much pressure on the master(s), it can cause cluster instability.

---

<div class="post-metadata">

**Author:** ![Andreas\_Falk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas_falk/32/82595_2.png) [@Andreas\_Falk](https://discuss.elastic.co/u/Andreas_Falk)\
**Post date:** [September 1, 2020, 7:12am UTC](https://discuss.elastic.co/t/creating-prod-cluster-with-ingest-nodes/247007/3 "2020-09-01T07:12:06Z")

</div>

@warkolm,  
Is it "better" to have the master roles on the data nodes?

--  
Regards Falk

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 1, 2020, 7:13am UTC](https://discuss.elastic.co/t/creating-prod-cluster-with-ingest-nodes/247007/4 "2020-09-01T07:13:09Z")

</div>

The best option is dedicated masters.

Whether data or ingest are better really comes down to your load profiles tbh.

---

<div class="post-metadata">

**Author:** ![Andreas\_Falk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas_falk/32/82595_2.png) [@Andreas\_Falk](https://discuss.elastic.co/u/Andreas_Falk)\
**Post date:** [September 1, 2020, 7:14am UTC](https://discuss.elastic.co/t/creating-prod-cluster-with-ingest-nodes/247007/5 "2020-09-01T07:14:59Z")

</div>

@warkolm Thanks, I'll have that in mind.

I have recently gotten really burned with ILM in our environment, and are now going back to native with no bells and whistles 🙂

--  
Regards Falk

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 1, 2020, 7:23am UTC](https://discuss.elastic.co/t/creating-prod-cluster-with-ingest-nodes/247007/6 "2020-09-01T07:23:02Z")

</div>

Ah ok, well it might be worth trying to resolve those ILM issues. It's definitely the path forward.

---

<div class="post-metadata">

**Author:** ![Andreas\_Falk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas_falk/32/82595_2.png) [@Andreas\_Falk](https://discuss.elastic.co/u/Andreas_Falk)\
**Post date:** [September 1, 2020, 7:25am UTC](https://discuss.elastic.co/t/creating-prod-cluster-with-ingest-nodes/247007/7 "2020-09-01T07:25:30Z")

</div>

I'm setting up a test cluster first now 🙂  
So that we don't have to do EVRYTNG in prod 🙄

Our infra group gets sad, but everyone alse wins..

--  
Regards Falk

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2020, 7:25am UTC](https://discuss.elastic.co/t/creating-prod-cluster-with-ingest-nodes/247007/8 "2020-09-29T07:25:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
