# Deployment architecture of ELK stack in on premise Windows Server

**URL:** <https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251>\
**Category:** Elasticsearch\
**Created:** [January 15, 2025, 8:56pm UTC](https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251 "2025-01-15T20:56:57Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![grootlin](https://avatars.discourse-cdn.com/v4/letter/g/46a35a/32.png) [@grootlin](https://discuss.elastic.co/u/grootlin)\
**Post date:** [January 15, 2025, 8:56pm UTC](https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251/1 "2025-01-15T20:56:57Z")

</div>

I have found myself as an administrator in an environment where ELK stack is used for log aggregation. We need to be pulling in Syslog data from our Network devices, virtualization cluster, and logs from our Windows / Linux machines using Elastic Agents.

A previous administrator had setup ELK stack on a Windows 2019 server. Here is some of the only documentation left behind pertaining to upgrading the ELK components, in an air gapped scenerio.

# Elastic Upgrade

1. Download Elasticsearch, Kibana and Logstash from their website

2. Place downloads in S:\Elastic\

3. Log into Server-ELS01

4. Unzip each ZIP file to C:\ElastickStack (They will have folder names like (-)

5. Stop all elastic Services

6. Rename Elastic Folders to .old

7. Elasticsearch → Elasticsearch.old

8. Kibana → Kibana.old

9. Logstash → Logstash.old

10. Rename new folders to original folder name

11. Elasticsearch-x.x.x → Elasticsearch

12. Kibana-x.x.x → Kibana

13. Logstash-x.x.x → Logstash

14. Reinstall the elastic service with the commands: (If I don't do this I get Java errors on startup)

15. cd \ElastickStack\elasticsearch\bin

16. elasticsearch-service.bat remove

17. elasticsearch-service.bat install

18. Set the service to automatic startup

19. Start the Elasticsearch service

20. Watch logs for errors in c:\Programdata\Elastic\Elasticsearch\logs

21. Once running, start the Kibana service

22. This will take a few minutes

23. Watch logs for errors in c:\Programdata\Elastic\kibana\logs

24. You should see and entry in the log "[INFO][status] Kibana is now available"

25. You can validate by logging into the web interface  
Once running, start the Logstash service  
Watch logs for errors in c:\Programdata\Elastic\logstash\logs

Java isn't even installed on the server. I am confused because there are elastic binaries that live under %programdata%, but the upgrade instructions show to update the elastic binaries in C:\ElasticStack where these files do exist. I need some general guidance on how you would do this basic single node deployment on windows 2019 so that I can try to piece this together. It seems like things are configured to send Elasticsearch data to the D drive and then backup snapshots onto our network storage, but also seems like logstash is not properly moving data from the queue.

Has anyone had experience with this basic architecture deployment who can explain generally how things should work? Resources you would point me to?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 17, 2025, 2:39am UTC](https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251/2 "2025-01-17T02:39:18Z")

</div>

I think elastic ships the proper Java bits.

---

<div class="post-metadata">

**Author:** ![grootlin](https://avatars.discourse-cdn.com/v4/letter/g/46a35a/32.png) [@grootlin](https://discuss.elastic.co/u/grootlin)\
**Post date:** [January 17, 2025, 2:13pm UTC](https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251/3 "2025-01-17T14:13:29Z")

</div>

I thought that may be the case, thanks for clarifying!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 17, 2025, 3:38pm UTC](https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251/4 "2025-01-17T15:38:34Z")

</div>

Hi @grootlin Welcome to the community.

I just saw this ... be very careful with instructions like that ... did you already try to execute them... if not... I would not... I would read our official documentation on Upgrading the Stack.

> **[Overview | Elastic Installation and Upgrade Guide \[8.17\] | Elastic](https://www.elastic.co/guide/en/elastic-stack/current/overview.html)**

Also, it is VERY important to understand What Version you are coming from and Going to. Not all upgrades are equal...

And yes JVM comes packaged with Elasticsearch and Logstash

---

<div class="post-metadata">

**Author:** ![grootlin](https://avatars.discourse-cdn.com/v4/letter/g/46a35a/32.png) [@grootlin](https://discuss.elastic.co/u/grootlin)\
**Post date:** [January 17, 2025, 4:17pm UTC](https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251/5 "2025-01-17T16:17:41Z")

</div>

Thanks for your reply. My deployment is on windows server. I haven't found documentation that is geared towards windows. And yes I attempted the upgrade which I ran into some shard limit issues, and ended up restoring to a clean snapshot. Thanks for your reply

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 17, 2025, 4:28pm UTC](https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251/6 "2025-01-17T16:28:08Z")

</div>

> **[Upgrade Elasticsearch | Elasticsearch Guide \[8.17\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.17/setup-upgrade.html)**

Detailed installation instructions

> **[Installing Elasticsearch | Elasticsearch Guide \[8.17\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.17/install-elasticsearch.html)**

Windows

> **[Install Elasticsearch with .zip on Windows | Elasticsearch Guide \[8.17\] |...](https://www.elastic.co/guide/en/elasticsearch/reference/8.17/zip-windows.html)**

Sounds like you may have succeeded but you should start to form your new upgrade path... Had you run those command across a major version it would not have worked...

So perhaps You got lucky this time and it was just a minor upgrade and that process would work.

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [January 18, 2025, 12:33am UTC](https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251/7 "2025-01-18T00:33:47Z")

</div>

is that "ran into some shard limit issues but were ultimately successful once I restored the snapshot, so problem solved" or "ran into some shard limit issues and ended up rolling back with help of the snapshot" ?

I'm gonna take a wild guess you hit the 1000 shard (default) limit.
