We need to deploy elastic stack in production to consume syslog data (amount of data is moderate)
During POC we deployed all ELK component in a single VM. In production how should we deploy ELK stack to ensure our environment is resilient.
- Elastic search - 3 VM (One master node, two data node) or I could have all three in single VM, do we actually need to create separate node?
2)One VM each for Kibana & Logstash?
- How resiliency can be achieved if my primary instance goes down, should we have separate instance of each component to achieve resiliency?
- Is there any component in elastic stack which takes care of resiliency like zookeeper ?