# Elasticsearch Load Balancer Recommendation

**URL:** <https://discuss.elastic.co/t/elasticsearch-load-balancer-recommendation/268286>\
**Category:** Beats\
**Tags:** filebeat, metricbeat, winlogbeat\
**Created:** [March 25, 2021, 4:21am UTC](https://discuss.elastic.co/t/elasticsearch-load-balancer-recommendation/268286 "2021-03-25T04:21:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![muthucse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muthucse/32/45217_2.png) [@muthucse](https://discuss.elastic.co/u/muthucse)\
**Post date:** [March 25, 2021, 4:21am UTC](https://discuss.elastic.co/t/elasticsearch-load-balancer-recommendation/268286/1 "2021-03-25T04:21:46Z")

</div>

The cluster has 5 hot nodes, 3 warm nodes and 3 dedicated master nodes (on-premise). We process the logs from multiple applications using Beats plugin. As we have option in Beats to add array of data nodes with loadbalance turned on.  
Based on the below criteria what's the best practice recommendation for load balancer.  
_Failover and recover._  
_No data loss even when a node goes down._  
_How to avoid extra overhead when we add more nodes to the cluster for scaling. Because with array of hosts we need to add new node when we include new node to the cluster and restart beats in every application._  
_Please suggest either to use array of hosts or separate load balancer ?_

---

<div class="post-metadata">

**Author:** ![muthucse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muthucse/32/45217_2.png) [@muthucse](https://discuss.elastic.co/u/muthucse)\
**Post date:** [March 25, 2021, 1:44pm UTC](https://discuss.elastic.co/t/elasticsearch-load-balancer-recommendation/268286/2 "2021-03-25T13:44:29Z")

</div>

@val - Appreciate, if you could provide your inputs.

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [March 25, 2021, 1:48pm UTC](https://discuss.elastic.co/t/elasticsearch-load-balancer-recommendation/268286/3 "2021-03-25T13:48:18Z")

</div>

What we usually do in this case is to hide all the ES nodes behind a load-balancer and reference the load balancer inside the Beats configuration. That gives you the flexibility to grow/shrink your cluster as you see fit without having to restart all your beats fleet.

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [March 25, 2021, 1:53pm UTC](https://discuss.elastic.co/t/elasticsearch-load-balancer-recommendation/268286/5 "2021-03-25T13:53:38Z")

</div>

From the [official doc](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#hosts-option)

> If one node becomes unreachable, the event is automatically sent to another node.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2021, 3:54pm UTC](https://discuss.elastic.co/t/elasticsearch-load-balancer-recommendation/268286/6 "2021-04-22T15:54:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
