# Elasticsearch-Output to Elasticsearch-Cluster

**URL:** <https://discuss.elastic.co/t/elasticsearch-output-to-elasticsearch-cluster/65532>\
**Category:** Logstash\
**Created:** [November 9, 2016, 5:07pm UTC](https://discuss.elastic.co/t/elasticsearch-output-to-elasticsearch-cluster/65532 "2016-11-09T17:07:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![TWalter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/twalter/32/41239_2.png) [@TWalter](https://discuss.elastic.co/u/TWalter)\
**Post date:** [November 9, 2016, 5:07pm UTC](https://discuss.elastic.co/t/elasticsearch-output-to-elasticsearch-cluster/65532/1 "2016-11-09T17:07:23Z")

</div>

Hello there,

i have an Elasticsearch-Cluster with three nodes. When i import the data to the cluster with the Elasticsearch-Output-Plugin, which node do i choose as Destination?

Is there a common expression for the host (maybe Cluster-Name). Or should i mention all three nodes in the host field? Or only one?

---

<div class="post-metadata">

**Author:** ![bhatch](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@bhatch](https://discuss.elastic.co/u/bhatch)\
**Post date:** [November 9, 2016, 9:35pm UTC](https://discuss.elastic.co/t/elasticsearch-output-to-elasticsearch-cluster/65532/2 "2016-11-09T21:35:30Z")

</div>

We have always just mentioned all of our data nodes.

---

<div class="post-metadata">

**Author:** ![TWalter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/twalter/32/41239_2.png) [@TWalter](https://discuss.elastic.co/u/TWalter)\
**Post date:** [November 9, 2016, 10:20pm UTC](https://discuss.elastic.co/t/elasticsearch-output-to-elasticsearch-cluster/65532/3 "2016-11-09T22:20:21Z")

</div>

My cluster is not very big. I have only three nodes and no specific data or master node. What if node 1 is a data node and I send data with logstash to it. And then the master goes down so that node 1 is the master. Is there a error because I send now the data to the master node, or is there a automatic handling ?

---

<div class="post-metadata">

**Author:** ![bhatch](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@bhatch](https://discuss.elastic.co/u/bhatch)\
**Post date:** [November 9, 2016, 10:52pm UTC](https://discuss.elastic.co/t/elasticsearch-output-to-elasticsearch-cluster/65532/4 "2016-11-09T22:52:07Z")

</div>

> [@TWalter](#):
>
> My cluster is not very big. I have only three nodes and no specific data or master node. What if node 1 is a data node and I send data with logstash to it. And then the master goes down so that node 1 is the master. Is there a error because I send now the data to the master node, or is there a automatic handling ?

There should be automatic handling. For a smaller cluster you should be able to send data to whatever node is available. But as you get larger it is recommended that you separate their duties more.

Take a look at this webpage. In particular the section about coordination nodes.  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html#coordinating-node](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html#coordinating-node)

> Requests like search requests or bulk-indexing requests may involve data held  
> on different data nodes. A search request, for example, is executed in two  
> phases which are coordinated by the node which receives the client request — the coordinating node.  
> In the scatter phase, the coordinating node forwards the request to the data  
> nodes which hold the data. Each data node executes the request locally and  
> returns its results to the coordinating node. In the gather phase, the  
> coordinating node reduces each data node’s results into a single global  
> resultset.  
> Every node is implicitly a coordinating node. This means that a node that has  
> all three node.master, node.data and node.ingest set to false will  
> only act as a coordinating node, which cannot be disabled. As a result, such  
> a node needs to have enough memory and CPU in order to deal with the gather  
> phase.

There is a warning on Master nodes though. While it should work, it isn't a good idea to have the Master node spend resources helping out with the searching and indexing of data. This extends to more than just coordination data, but also storing data itself. It is recommended to have Master and Data nodes be completely separate.

> While master nodes can also behave as coordinating nodes  
> and route search and indexing requests from clients to data nodes, it is  
> better not to use dedicated master nodes for this purpose. It is important  
> for the stability of the cluster that master-eligible nodes do as little work  
> as possible.

---

<div class="post-metadata">

**Author:** ![TWalter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/twalter/32/41239_2.png) [@TWalter](https://discuss.elastic.co/u/TWalter)\
**Post date:** [December 2, 2016, 8:15am UTC](https://discuss.elastic.co/t/elasticsearch-output-to-elasticsearch-cluster/65532/5 "2016-12-02T08:15:14Z")

</div>

Thanks for your advice =)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2016, 8:15am UTC](https://discuss.elastic.co/t/elasticsearch-output-to-elasticsearch-cluster/65532/6 "2016-12-30T08:15:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
