# Elastic Search Cluster Doubts

**URL:** <https://discuss.elastic.co/t/elastic-search-cluster-doubts/27580>\
**Category:** Elasticsearch\
**Created:** [August 18, 2015, 11:16am UTC](https://discuss.elastic.co/t/elastic-search-cluster-doubts/27580 "2015-08-18T11:16:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zeal\_Vora](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zeal_vora/32/3946_2.png) [@Zeal\_Vora](https://discuss.elastic.co/u/Zeal_Vora)\
**Post date:** [August 18, 2015, 11:16am UTC](https://discuss.elastic.co/t/elastic-search-cluster-doubts/27580/1 "2015-08-18T11:16:03Z")

</div>

Hi

I have setup a 3 Node Elastic Search Cluster. This is the detail of my cluster :-

{  
"cluster\_name" : "pokemon",  
"status" : "green",  
"timed\_out" : false,  
"number\_of\_nodes" : 3,  
"number\_of\_data\_nodes" : 3,  
"active\_primary\_shards" : 1,  
"active\_shards" : 2,  
"relocating\_shards" : 0,  
"initializing\_shards" : 0,  
"unassigned\_shards" : 0,  
"number\_of\_pending\_tasks" : 0,  
"number\_of\_in\_flight\_fetch" : 0  
}

So i was wondering on which node should i configure my fluentd to send data ? For sample test, i tried sending data from logstash to one of the nodes on 9200 but it doesn't seem to work.

Also, is the above configuration proper one ? I just need proper replication so if master goes down, the other machine can take it's place.

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 18, 2015, 11:28am UTC](https://discuss.elastic.co/t/elastic-search-cluster-doubts/27580/2 "2015-08-18T11:28:12Z")

</div>

> So i was wondering on which node should i configure my fluentd to send data ?

Either one. It doesn't matter. If possible, configure the client (fluentd in this case) to know about all cluster nodes so that it can try to connect to all of them. Otherwise if you hardcode to a single hostname you have a problem if that node goes down. Alternatively, use HAproxy or similar as a frontend.

> For sample test, i tried sending data from logstash to one of the nodes on 9200 but it doesn't seem to work.

Well, it should work but without further details it's impossible to tell. What's in the Logstash logs?

> Also, is the above configuration proper one ? I just need proper replication so if master goes down, the other machine can take it's place.

You have one replica of each shard so you can handle a single node being down.

---

<div class="post-metadata">

**Author:** ![Zeal\_Vora](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zeal_vora/32/3946_2.png) [@Zeal\_Vora](https://discuss.elastic.co/u/Zeal_Vora)\
**Post date:** [August 18, 2015, 11:50am UTC](https://discuss.elastic.co/t/elastic-search-cluster-doubts/27580/3 "2015-08-18T11:50:53Z")

</div>

thanks alot magnumsbaeck.

I get following exception in my logstash.log

timestamp=\>"2015-08-18T11:47:45.904000+0000", :message=\>"Failed to flush outgoing items", :outgoing\_count=\>37, :exception=\>org.elasticsearch.cluster.block.ClusterBlockException: blocked by: [SERVICE\_UNAVAILABLE/1/state not recovered / initialized];[SERVICE\_UNAVAILABLE/2/no master];, :backtrace=\>["org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedException(org/elasticsearch/cluster/block/ClusterBlocks.java:151)

This is my sample configuration across my 3 nodes :-

node.name: "pikachu"  
cluster.name: pokemon  
discovery.zen.ping.unicast.hosts: ["pichu"]  
discovery.zen.ping.multicast.enabled: false

Do i have to select some master ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 18, 2015, 11:57am UTC](https://discuss.elastic.co/t/elastic-search-cluster-doubts/27580/4 "2015-08-18T11:57:28Z")

</div>

What's your Logstash output configuration? Are you setting the [`cluster`](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-cluster) configuration option to "pokemon"?

---

<div class="post-metadata">

**Author:** ![Zeal\_Vora](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zeal_vora/32/3946_2.png) [@Zeal\_Vora](https://discuss.elastic.co/u/Zeal_Vora)\
**Post date:** [August 18, 2015, 12:07pm UTC](https://discuss.elastic.co/t/elastic-search-cluster-doubts/27580/5 "2015-08-18T12:07:14Z")

</div>

The cluser.name is pokemon for all the 3 nodes

I tried running logstash in other 2 cluster nodes and i don't seem to get any errors in logstash.log , however when i open kibana, i can't find any data either.

This is my logstash configuration :-

input {  
file {  
path =\> "/var/log/messages"  
start\_position =\> "beginning"  
}  
}

output {  
stdout { }  
elasticsearch {  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 18, 2015, 12:18pm UTC](https://discuss.elastic.co/t/elastic-search-cluster-doubts/27580/6 "2015-08-18T12:18:16Z")

</div>

> The cluser.name is pokemon for all the 3 nodes

Yes, but you're not configuring _Logstash_ to connect to that cluster. Use the `cluster` option, and since you've disabled multicast you have to set the [`host`](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-host) to point to least one of the cluster nodes.

```
output {
  elasticsearch {
    cluster => "pokemon"
    host => ["es-host1.example.com"]
  }
}

```

---

<div class="post-metadata">

**Author:** ![Zeal\_Vora](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zeal_vora/32/3946_2.png) [@Zeal\_Vora](https://discuss.elastic.co/u/Zeal_Vora)\
**Post date:** [August 18, 2015, 12:40pm UTC](https://discuss.elastic.co/t/elastic-search-cluster-doubts/27580/7 "2015-08-18T12:40:06Z")

</div>

> [@](#):
>
> Yes, but you're not configuring Logstash to connect to that cluster. Use the cluster option, and since you've disabled multicast you have to set the host to point to least one of the cluster nodes.

Awesome. It's working now. I've also pointed my fluentd which is running on the client side to point to one of the IP's in the cluster and Elastic Search seems to be receiving logs.

I've also set : discovery.zen.minimum\_master\_nodes = 2

Is it recommended to use HA Proxy or i can maybe tell fluentd in someway of sending logs to 1 server in cluster and if it goes down ( not reachable ) it should send to the other server IP.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:55pm UTC](https://discuss.elastic.co/t/elastic-search-cluster-doubts/27580/8 "2017-07-05T23:55:19Z")

</div>


