# ElasticSearch Size Recommendation

**URL:** <https://discuss.elastic.co/t/elasticsearch-size-recommendation/80774>\
**Category:** Elasticsearch\
**Created:** [March 31, 2017, 5:29am UTC](https://discuss.elastic.co/t/elasticsearch-size-recommendation/80774 "2017-03-31T05:29:19Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Feedy](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@Feedy](https://discuss.elastic.co/u/Feedy)\
**Post date:** [March 31, 2017, 5:29am UTC](https://discuss.elastic.co/t/elasticsearch-size-recommendation/80774/1 "2017-03-31T05:29:19Z")

</div>

TLDR: what specs are appropriate for client, data, and master nodes when ingesting 250GB/day?

Hi All,  
I've been tasked with building out an ELK Stack as my company would like to move away from Splunk. We've already began using the ELK Stack template that AWS provides but we would like more control over configuration. With that being said, I've been reading a lot of documents and I think I have a good idea of the specs for each node but still wanted to reach out to the community in case someone had a more definitive answer. This clustered ELK environment would be ingesting around 250GB/day and possibly growing in the near future. This is what I was thinking:  
10 total nodes  
2 client nodes  
3 data nodes  
3 master nodes  
1 Kibana  
2 Logstash

From my reading I have leaned that the master node doesn't require that much in RAM and HD so I figure maybe 8GB in RAM and 50 in HD?  
From my reading I have learned that the data nodes work best at 64GB but still works well at 32GB. I was thinking maybe 2TB for each data node. At least 1yr retention on indexes.  
I am not sure at all what the specs should be for the client nodes?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 31, 2017, 5:50am UTC](https://discuss.elastic.co/t/elasticsearch-size-recommendation/80774/2 "2017-03-31T05:50:34Z")

</div>

As each shard holds a finite amount of data and is associated with some overhead in terms of memory, file handles and CPU, the more hap you have on a node the more data it can hold. As we generally recommend heap to be \< 32GB and 50% of available RAM to be used for heap, 64GB RAM per node is often considered the sweet spot.

As dedicated master nodes are not serving traffic and just manage the cluster, they generally just need a few CPU cores and 4-8GB RAM. As they do not hold data, heap can be set to 75% of the available host memory. Client nodes may be useful, but are generally not necessary for a lot of logging use cases.

If you have 250GB per day and want to keep that for 1 year, that corresponds to around 90TB of raw data. Based on that I would expect you to need more disk space on the data nodes as well as a larger number of data nodes. Exactly how much space that amount of data will take up on disk once indexed will largely depend on how you optimise your mappings. Although it is getting a bit old, [this blog post](https://www.elastic.co/blog/elasticsearch-storage-the-true-story-2.0) illustrates the effect different mappings can have.

---

<div class="post-metadata">

**Author:** ![Feedy](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@Feedy](https://discuss.elastic.co/u/Feedy)\
**Post date:** [March 31, 2017, 2:42pm UTC](https://discuss.elastic.co/t/elasticsearch-size-recommendation/80774/3 "2017-03-31T14:42:51Z")

</div>

Hi Christian\_Dahlqvist,

Thanks you for that information. What's the difference between a client node and a coordinating node? I believe they are the same correct?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 31, 2017, 2:50pm UTC](https://discuss.elastic.co/t/elasticsearch-size-recommendation/80774/4 "2017-03-31T14:50:44Z")

</div>

Yes, they are the same.

---

<div class="post-metadata">

**Author:** ![Feedy](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@Feedy](https://discuss.elastic.co/u/Feedy)\
**Post date:** [March 31, 2017, 2:52pm UTC](https://discuss.elastic.co/t/elasticsearch-size-recommendation/80774/5 "2017-03-31T14:52:42Z")

</div>

Also, what about an ingest node? Sorry I found a new document(there are so many ;-).....Where does the ingest node come into play? Is it the same as Logstash?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 31, 2017, 2:55pm UTC](https://discuss.elastic.co/t/elasticsearch-size-recommendation/80774/6 "2017-03-31T14:55:56Z")

</div>

Ingest node is a new node type in Elasticsearch 5.x which allows you to transform indexing requests prior to writing them to Elasticsearch. It supports a subset of the functionality available in Logstash and can allow for a simpler architecture in some cases. If you decide to use them, you should probably use dedicated ingest nodes as they like Logstash can be CPU intensive.

---

<div class="post-metadata">

**Author:** ![Feedy](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@Feedy](https://discuss.elastic.co/u/Feedy)\
**Post date:** [March 31, 2017, 5:56pm UTC](https://discuss.elastic.co/t/elasticsearch-size-recommendation/80774/7 "2017-03-31T17:56:07Z")

</div>

ook got it. Thanks again. I will take this information you provided and begin building!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2017, 5:56pm UTC](https://discuss.elastic.co/t/elasticsearch-size-recommendation/80774/8 "2017-04-28T17:56:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
