My cluster is not very big. I have only three nodes and no specific data or master node. What if node 1 is a data node and I send data with logstash to it. And then the master goes down so that node 1 is the master. Is there a error because I send now the data to the master node, or is there a automatic handling ?
Requests like search requests or bulk-indexing requests may involve data held
on different data nodes. A search request, for example, is executed in two
phases which are coordinated by the node which receives the client request — the coordinating node.
In the scatter phase, the coordinating node forwards the request to the data
nodes which hold the data. Each data node executes the request locally and
returns its results to the coordinating node. In the gather phase, the
coordinating node reduces each data node’s results into a single global
Every node is implicitly a coordinating node. This means that a node that has
all three node.master, node.data and node.ingest set to false will
only act as a coordinating node, which cannot be disabled. As a result, such
a node needs to have enough memory and CPU in order to deal with the gather
There is a warning on Master nodes though. While it should work, it isn't a good idea to have the Master node spend resources helping out with the searching and indexing of data. This extends to more than just coordination data, but also storing data itself. It is recommended to have Master and Data nodes be completely separate.
While master nodes can also behave as coordinating nodes
and route search and indexing requests from clients to data nodes, it is
better not to use dedicated master nodes for this purpose. It is important
for the stability of the cluster that master-eligible nodes do as little work