# Elasticsearch cluster - please review my configuration and advise

**URL:** <https://discuss.elastic.co/t/elasticsearch-cluster-please-review-my-configuration-and-advise/259502>\
**Category:** Elasticsearch\
**Created:** [December 23, 2020, 3:26pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-please-review-my-configuration-and-advise/259502 "2020-12-23T15:26:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ged](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ged/32/65761_2.png) [@Ged](https://discuss.elastic.co/u/Ged)\
**Post date:** [December 23, 2020, 3:26pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-please-review-my-configuration-and-advise/259502/1 "2020-12-23T15:26:19Z")

</div>

Hi Team,

I want to share my ELK stack cluster configuration shown below asking you to review it and share your thoughts and answer some questions.

 ![ELK Stack Cert 2](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3cff6a548bf4e96129bda9613f99b2c02f5833c9.png)

Elasticsearch nodes configuration for ELK SERVER A1 and ELK SERVER B1:  
node.master: true  
node.data: true  
node.ingest: false  
node.ml: false  
xpack.ml.enabled: false  
cluster.remote.connect: false

Elasticsearch nodes configuration for ELK SERVER A2 and ELK SERVER B2:  
node.master: true  
node.data: false  
node.ingest: false  
node.ml: false  
xpack.ml.enabled: false  
cluster.remote.connect: false

Data flow is:

1. App servers in both datacenters push data via UDP to Logstashes (using UDP input plugin):

- those in DC A to Logstash on ELK SERVER A2
- those in DC B to Logstash on ELK SERVER B2

1. Logstashes forward data to Elasticsearch data nodes:

- Logstash on ELK SERVER A2 to Elasticsearch data node on ELK SERVER A1
- Logstash on ELK SERVER B2 to Elasticsearch data node on ELK SERVER B1

1. Data is replicated between Elasticsearch data nodes on ELK SERVER A1 and ELK SERVER B1

2. Kibana instances are connected to:

- on ELK SERVER A1 to Elasticsearch data nodes on ELK SERVER A1
- on ELK SERVER B1 to Elasticsearch data nodes on ELK SERVER B1

My questions:

1. Is it OK to push data from Logstashes to Elasticsearch data nodes ? If not, what is the best approach ?
2. Is it OK for both Kibana instances to be connected as described above ?
3. Or maybe all my configuration is not recommended and i should create all the ELK stack in another way ?

Thank you in advance !  
Ged

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 26, 2020, 10:12am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-please-review-my-configuration-and-advise/259502/2 "2020-12-26T10:12:25Z")

</div>

> [@Ged](#):
>
> 1. Logstashes forward data to Elasticsearch data nodes:
> 
> - Logstash on ELK SERVER A2 to Elasticsearch data node on ELK SERVER A1
> - Logstash on ELK SERVER B2 to Elasticsearch data node on ELK SERVER B1

Both Logstash instances should ideally have both Elasticsearch data nodes configured so you do not lose data if one is unavailable.

> [@Ged](#):
>
> Is it OK to push data from Logstashes to Elasticsearch data nodes ? If not, what is the best approach ?

Yes, that is the best option in this scenario.

> [@Ged](#):
>
> Is it OK for both Kibana instances to be connected as described above ?

It would be good for Kibana to also be able to connect to all any data node for failover.

> [@Ged](#):
>
> Or maybe all my configuration is not recommended and i should create all the ELK stack in another way ?

It looks like you have tried to design for high availability and given the outlined configuration you will be able to handle a single node going down without losing access to the cluster. It is however worth noting that if you want to be able to continue operating if the two data centers get disconnected or one crashes completely, you will need a third data center. [It is impossible to deploy Elasticsearch in a highly available way (with respect to data centre failure) across just 2 data centres](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/high-availability-cluster-small-clusters.html).

---

<div class="post-metadata">

**Author:** ![Ged](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ged/32/65761_2.png) [@Ged](https://discuss.elastic.co/u/Ged)\
**Post date:** [January 8, 2021, 11:07am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-please-review-my-configuration-and-advise/259502/3 "2021-01-08T11:07:37Z")

</div>

Many thanks for you advise Christian !  
I have one more question:  
When connecting Logstash/Kibana to two Elasticsearch nodes how requests are balanced ? Si it round-robin ? Or maybe it's configurable and it's possible to use master/failover ? I mean sending requests to master if available and if it's down sending to failover one ?

Thank you !  
Ged

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2021, 11:07am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-please-review-my-configuration-and-advise/259502/4 "2021-02-05T11:07:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
