# Deployment Architecture Scenarios Using ELK for SIEM at Large Scale on-promise

**URL:** <https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525>\
**Category:** SIEM\
**Created:** [April 30, 2024, 10:13pm UTC](https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525 "2024-04-30T22:13:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![NasrJBr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nasrjbr/32/134034_2.png) [@NasrJBr](https://discuss.elastic.co/u/NasrJBr)\
**Post date:** [April 30, 2024, 10:13pm UTC](https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525/1 "2024-04-30T22:13:11Z")

</div>

i want to create some scenarios of deployment of ELK for SIEM usage in a large scale. any help/suggestions about this ?

---

<div class="post-metadata">

**Author:** ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)\
**Post date:** [May 1, 2024, 2:44pm UTC](https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525/2 "2024-05-01T14:44:44Z")

</div>

Hello, @NasrJBr!

For a general starting point, I suggest reviewing the [ingest architecture guide](https://www.elastic.co/guide/en/ingest/current/use-case-arch.html) from the Elastic docs.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 1, 2024, 2:49pm UTC](https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525/3 "2024-05-01T14:49:43Z")

</div>

@ebeahan Is this documentation new? Didn't know it, it is pretty good.

I think that this [one](https://www.elastic.co/guide/en/ingest/current/agent-kafka-es.html) can be updated now that th Elastic Agent can ship directly to Kafka.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 1, 2024, 3:02pm UTC](https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525/4 "2024-05-01T15:02:19Z")

</div>

> [@NasrJBr](#):
>
> i want to create some scenarios of deployment of ELK for SIEM usage in a large scale. any help/suggestions about this ?

I deployed a couple and what I always did to help it scale was:

- Have dedicated masters from the beginning, 3 master nodes will be enough for the majority of the cases.
- Have data tiers from the beginning
- Use Kafka as a message queue for data sources with high volume
- Use Elastic Agent integrations when possible

So I have almost everything sending data to Kafka and then Logstash consuming this data and sending to Elasticsearch, in some cases I have Elastic Agents sending data directly to Elasticsearch.

For network devices, I send the data to some logstash that its only function will be to ship the data to Kafka, this can be replaced with lighter tools like Filebeat or Vector from Datadog.

An example of architecture is this:

- 5 machines for Elasticsearch, where 3 are master dedicated and 2 are data\_hot/data\_content/ingest nodes.
- 1 Machine for Kibana
- 1 Machine for Fleet server
- 3 Machines for a Kafka cluster
- 2 Logstash for receiving data and sending to kafka
- 2 Logstash for reading from kafka, parsing the data, and sending to Elasticsearch

Of course this can be changed depending on the requirements and budget.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 1, 2024, 3:35pm UTC](https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525/7 "2024-05-01T15:35:36Z")

</div>

> [@NasrJBr](#):
>
> I understand the concept, but could you guide me on how to calculate the required number of machines for each module?

This depends entirely on your requirements, for example, if you have just one datacenter, if you have multiple datacenters/locations from where you need to get data, what kind of data you need etc.

On the previous answer I already gave an example of some distribution of machines.

---

<div class="post-metadata">

**Author:** ![NasrJBr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nasrjbr/32/134034_2.png) [@NasrJBr](https://discuss.elastic.co/u/NasrJBr)\
**Post date:** [May 1, 2024, 3:49pm UTC](https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525/8 "2024-05-01T15:49:59Z")

</div>

Thank you @leandrojmp.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2024, 3:50pm UTC](https://discuss.elastic.co/t/deployment-architecture-scenarios-using-elk-for-siem-at-large-scale-on-promise/358525/9 "2024-05-29T15:50:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
