# Elasticsearch node Sizing for production

**URL:** <https://discuss.elastic.co/t/elasticsearch-node-sizing-for-production/186204>\
**Category:** Elasticsearch\
**Created:** [June 18, 2019, 8:56am UTC](https://discuss.elastic.co/t/elasticsearch-node-sizing-for-production/186204 "2019-06-18T08:56:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![TsuWeiQuan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsuweiquan/32/46252_2.png) [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)\
**Post date:** [June 18, 2019, 8:56am UTC](https://discuss.elastic.co/t/elasticsearch-node-sizing-for-production/186204/1 "2019-06-18T08:56:35Z")

</div>

Hello,

I am currently doing some research and designing the architecture for the ELK stack to be used in production. My team has purchased 9 elastic nodes for this setup.  
However, I have some questions on the sizing of the elasticsearch nodes.

I expect 350 systems to be sending logs into elasticsearch and it is estimated that one system would send 50 MB logs per day.

We are also storing the logs for 180 days only before deleting them.

Index would rollover daily or logs exceeds 30GB

```
1 day --> 1 system --> 2 shards --> 100MB
180 days --> 1 system --> 360 shards --> 18GB
180 days --> 350 system --> 126000 shards --> 6.3TB

```

Furthermore, I planned to have

```
Primary Shards: 1
Replica Shards: 1

```

and planned to give my VMs these specs:

```
3 x Master node:
CPU: 4
RAM: 16GB
DISK: 50GB

6 x Data node:
CPU: 8
RAM: 32GB
DISK: 2TB

```

![image](https://us1.discourse-cdn.com/elastic/original/3X/f/d/fde69f12dcc3032ab617f7847e21eddc0d89fe5b.png)  
I am unsure if these settings are ideal for the environment now, hence requesting advice.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 18, 2019, 9:04am UTC](https://discuss.elastic.co/t/elasticsearch-node-sizing-for-production/186204/2 "2019-06-18T09:04:17Z")

</div>

If you have low data volumes try using monthly rather than daily indices. Shards should ideally be over 10GB in size. Also try storing data from multiple systems in the same indices to reduce the total number of shards to hundreds rather than thousands.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 18, 2019, 9:09am UTC](https://discuss.elastic.co/t/elasticsearch-node-sizing-for-production/186204/3 "2019-06-18T09:09:04Z")

</div>

Agreed with @Christian_Dahlqvist.

Just want to share some resources about sizing:

[https://www.elastic.co/elasticon/conf/2016/sf/quantitative-cluster-sizing](https://www.elastic.co/elasticon/conf/2016/sf/quantitative-cluster-sizing)

> **[How many shards should I have in my Elasticsearch cluster?](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster)**
>
> If you are looking for practical guidelines around how many indices and shards to have in your cluster, this blog post will help you avoid common pitfalls.

https://www.slideshare.net/slideshow/embed_code/key/vR0XKDq4TGa77z

And [https://www.elastic.co/webinars/using-rally-to-get-your-elasticsearch-cluster-size-right](https://www.elastic.co/webinars/using-rally-to-get-your-elasticsearch-cluster-size-right)

---

<div class="post-metadata">

**Author:** ![TsuWeiQuan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsuweiquan/32/46252_2.png) [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)\
**Post date:** [June 18, 2019, 9:31am UTC](https://discuss.elastic.co/t/elasticsearch-node-sizing-for-production/186204/4 "2019-06-18T09:31:55Z")

</div>

I see, thanks @dadoonet and @Christian_Dahlqvist forr the quick reply!  
I think can try to rollover/month and reduce my shards to 144 / cycle

```
1 day --> 1 system --> 2 shards --> 100MB
180 days --> 1 system --> 8 shards --> 18GB
180 days --> 350 system --> 144 shards --> 6.3TB

```

I will read up on the given documents.

However, I wonder if the DISK size & RAM size on elasticsearch node is ideally enough for such purpose?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 18, 2019, 10:14am UTC](https://discuss.elastic.co/t/elasticsearch-node-sizing-for-production/186204/5 "2019-06-18T10:14:36Z")

</div>

I suspect that you can even try with one single shard for 18gb of data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2019, 10:14am UTC](https://discuss.elastic.co/t/elasticsearch-node-sizing-for-production/186204/6 "2019-07-16T10:14:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
