# Elastic siem and EDR architecture validation

**URL:** <https://discuss.elastic.co/t/elastic-siem-and-edr-architecture-validation/390884>\
**Category:** Elasticsearch\
**Created:** [October 6, 2026, 8:39pm UTC](https://discuss.elastic.co/t/elastic-siem-and-edr-architecture-validation/390884 "2026-10-06T20:39:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![chandrakt](https://avatars.discourse-cdn.com/v4/letter/c/e9c0ed/32.png) [@chandrakt](https://discuss.elastic.co/u/chandrakt)\
**Post date:** [October 6, 2026, 8:39pm UTC](https://discuss.elastic.co/t/elastic-siem-and-edr-architecture-validation/390884/1 "2026-10-06T20:39:37Z")

</div>

![OT SOC Elastic SIEM DC–DR Architecture](https://us1.discourse-cdn.com/elastic/original/3X/1/9/192973f5e105b6ac2239b7c888ca54079eae30d3.jpeg)please let me know isthis correct diagram for 50gb par day dat ingestion and i need DC and DR both

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 6, 2026, 9:22pm UTC](https://discuss.elastic.co/t/elastic-siem-and-edr-architecture-validation/390884/2 "2026-10-06T21:22:15Z")

</div>

Hello and welcome,

> [@chandrakt](#):
>
> please let me know isthis correct diagram for 50gb par day dat ingestion and i need DC and DR both

Is this estimate of 50 GB/day correct? This is very small and your configuration is extremelly overkill for it.

How did you arrive to this number?

The overall design is ok, I have a similar one specially the logstash + kafka + logstash, but some things are a little confusing.

First, your logstash layer that act as producers do not exist in your DR, so your DR would be only for querying the existing data, right?

Another thing, Fleet is used to manage Elastic Agents, and Elastic Agents can be enrolled to one cluster only, there is no reason to have DR fleet servers unless every time you change to DR you reenroll all your agents into the DR cluster.

Also, as far as I know MinIO is deprecated, what would be the use here? Local object storage compatible with s3 api to use on frozen tiers? I'm not sure what is being used on-premises now, but since this requires a paid license it may be better to reach to elastic to have some help designing your cluster.

---

<div class="post-metadata">

**Author:** ![chandrakt](https://avatars.discourse-cdn.com/v4/letter/c/e9c0ed/32.png) [@chandrakt](https://discuss.elastic.co/u/chandrakt)\
**Post date:** [October 7, 2026, 3:05am UTC](https://discuss.elastic.co/t/elastic-siem-and-edr-architecture-validation/390884/3 "2026-10-07T03:05:15Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/8/a84f32d7c186b3ec4cf06291a9c6e73fc7b9c3b0.png)

this arch recommended by OEM for multisite having DR and below is the sizing details also recommende by OEM

| Aspect | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Data Ingestion per day | 50 GB | | | | | | | |
| Retention Period | 1 year - 10 days hot | 20 days cold | 335 days frozen | | | | | | | |
| Deployement | Self managed | | | | | | | |
| | | | | | | | | |
| | | | | | | | | |
| | Total RAM (GB) | Total Storage (TB) | Object Storage(MinIO) (TB) | | | | | |
| Hot | 30 | 0.8 | | | | | | |
| Cold | 16 | 1.2 | | | | | | |
| Frozen | 8 | 0.6 | 10.1 | | | | | |
| Kibana | 8 | | | | | | | |
| Total RAM | 62 | | | | | | | |
| | | | | | | | | |
| BOQ | | | | | | | | |
| Data Tier | Nodes | Total CPU | Total RAM | Total Storage(TB) | Object Storage(TB) | Type of Disk | | |
| Hot | 2 | 16 | 30 | 0.8 | | SSD/NVME | | |
| Cold | 2 | 8 | 16 | 1.2 | | Dense HDD | | |
| Frozen | 1 | 4 | 8 | 0.6 | 10.1 | Object Storage | | |
| Non Data Nodes | nodes | Total CPU | Total RAM | Storage(GB) | | Type of Disk | | |
| Kibana nodes | 2 | 4 | 8 | 300 | | SSD/NVME now let me know how shall i create architecture for customer having 60 endpoints from where we will take data and this is OT/IT SOC setup in which they have below telemetry | | |

**Requirement**  
**Detail**  
Current SIEM ingestion  
Approximately 50 GB/day  
EDR scope  
35 workstations + 25 servers, including 4 Linux servers  
Current SIEM source  
Netka Syslog
