# Elastic Stack Production deployment

**URL:** <https://discuss.elastic.co/t/elastic-stack-production-deployment/192361>\
**Category:** Elasticsearch\
**Created:** [July 26, 2019, 6:06am UTC](https://discuss.elastic.co/t/elastic-stack-production-deployment/192361 "2019-07-26T06:06:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![singh.piyush862](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@singh.piyush862](https://discuss.elastic.co/u/singh.piyush862)\
**Post date:** [July 26, 2019, 6:06am UTC](https://discuss.elastic.co/t/elastic-stack-production-deployment/192361/1 "2019-07-26T06:06:19Z")

</div>

We need to deploy elastic stack in production to consume syslog data (amount of data is moderate)  
During POC we deployed all ELK component in a single VM. In production how should we deploy ELK stack to ensure our environment is resilient.

1. Elastic search - 3 VM (One master node, two data node) or I could have all three in single VM, do we actually need to create separate node?  
2)One VM each for Kibana & Logstash?
2. How resiliency can be achieved if my primary instance goes down, should we have separate instance of each component to achieve resiliency?
3. Is there any component in elastic stack which takes care of resiliency like zookeeper ?

---

<div class="post-metadata">

**Author:** ![harshbajaj16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshbajaj16/32/44970_2.png) [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Post date:** [July 26, 2019, 6:46am UTC](https://discuss.elastic.co/t/elastic-stack-production-deployment/192361/2 "2019-07-26T06:46:14Z")

</div>

Hi @singh.piyush862,

Please find my inline response on your queries:

> [@singh.piyush862](#):
>
> Elastic search - 3 VM (One master node, two data node) or I could have all three in single VM, do we actually need to create separate node?

Yes, you should create different VMs for different ES node. In case you create all ES on one VM and VM goes down then all ES goes down. However, elastic community recommend running 3 dedicated master nodes per cluster having dedicated master nodes which run in their own JVM increases stability and resilience as they are not affected by garbage collection that can affect other types of nodes. These nodes do not handle requests and do not hold any data, and therefore only require less resources (such as CPU, RAM and Disk).

> [@](#):
>
> 2)One VM each for Kibana & Logstash?

Yes, VMs shoud be seprate for both components.

> [@singh.piyush862](#):
>
> - How resiliency can be achieved if my primary instance goes down, should we have separate instance of each component to achieve resiliency?
> - Is there any component in elastic stack which takes care of resiliency like zookeeper ?

You can achieve the resiliency using recommended cluster and Hot-Warm architecture in elasticsearch as there is no components like zookeeper in elasticsearch.

Reagrds,  
Harsh Bajaj

---

<div class="post-metadata">

**Author:** ![singh.piyush862](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@singh.piyush862](https://discuss.elastic.co/u/singh.piyush862)\
**Post date:** [August 2, 2019, 11:30am UTC](https://discuss.elastic.co/t/elastic-stack-production-deployment/192361/3 "2019-08-02T11:30:33Z")

</div>

Thanks Harsh, Appreciate your comments

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2019, 11:30am UTC](https://discuss.elastic.co/t/elastic-stack-production-deployment/192361/4 "2019-08-30T11:30:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
