# ELK Architecture and requirements

**URL:** <https://discuss.elastic.co/t/elk-architecture-and-requirements/101075>\
**Category:** Elasticsearch\
**Created:** [September 19, 2017, 9:38pm UTC](https://discuss.elastic.co/t/elk-architecture-and-requirements/101075 "2017-09-19T21:38:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nelson\_Pita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nelson_pita/32/89038_2.png) [@Nelson\_Pita](https://discuss.elastic.co/u/Nelson_Pita)\
**Post date:** [September 19, 2017, 9:38pm UTC](https://discuss.elastic.co/t/elk-architecture-and-requirements/101075/1 "2017-09-19T21:38:08Z")

</div>

Hi guys,

I need to create an ELK architecture but I don't know how many servers and requirements (CPU, RAM,Disk space) I will need.  
I will need to send syslog and logfiles from 15 servers (total around 500MB/day) to this ELK and have almost 60 days retention.  
I also will need to separate in 3 tiers (web - kibana, app - logstash, db - elasticsearch) and I also want high availability.  
So if the operating system is Red Hat Enterprise Linux 7 what should be the correct architecture?

Thanks,  
Nelson

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 20, 2017, 12:48am UTC](https://discuss.elastic.co/t/elk-architecture-and-requirements/101075/2 "2017-09-20T00:48:30Z")

</div>

You want at least 3 nodes, and that should hold your expected dataset.

Also we’ve renamed ELK to the Elastic Stack, otherwise Beats feels left out 😉

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [September 20, 2017, 8:46am UTC](https://discuss.elastic.co/t/elk-architecture-and-requirements/101075/3 "2017-09-20T08:46:22Z")

</div>

For that load pretty much any 3 modern machines will do fine. As for requirements _more is more_ 🙂

> **[Hardware | Elasticsearch: The Definitive Guide \[2.x\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/guide/current/hardware.html)**

> RAM:  
> A machine with 64 GB of RAM is the ideal sweet spot, but 32 GB and 16 GB machines are also common. Less than 8 GB tends to be counterproductive...
> 
> CPUs:  
> Most Elasticsearch deployments tend to be rather light on CPU requirements. As such, the exact processor setup matters less than the other resources. You should choose a modern processor with multiple cores. Common clusters utilize two- to eight-core machines.
> 
> Disk:  
> If you can afford SSDs, they are by far superior to any spinning media. SSD-backed nodes see boosts in both query and indexing performance....

Even with 1 TB of disk per node you would have 3TB / 2 (if you use one replica per shard) for your indices. 1500GB (total storage) /0.5 GB (daily data) = 3000 days of retention 😛

---

<div class="post-metadata">

**Author:** ![Nelson\_Pita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nelson_pita/32/89038_2.png) [@Nelson\_Pita](https://discuss.elastic.co/u/Nelson_Pita)\
**Post date:** [September 25, 2017, 2:12pm UTC](https://discuss.elastic.co/t/elk-architecture-and-requirements/101075/4 "2017-09-25T14:12:05Z")

</div>

Hi Mark,

What do you mean with 3 nodes? 1 node for each tier??  
And what about 2 servers for logstash, 2 servers for kibana and 3 server for elasticsearch?  
For elasticsearch, how many master, ingest and data nodes I need?

Thanks,  
Nelson Pita

---

<div class="post-metadata">

**Author:** ![Nelson\_Pita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nelson_pita/32/89038_2.png) [@Nelson\_Pita](https://discuss.elastic.co/u/Nelson_Pita)\
**Post date:** [September 25, 2017, 2:13pm UTC](https://discuss.elastic.co/t/elk-architecture-and-requirements/101075/5 "2017-09-25T14:13:31Z")

</div>

Hi,

How many servers by tier? What about 2 servers for logstash, 2 servers for kibana and 3 server for elasticsearch?  
For elasticsearch, how many master, ingest and data nodes I need?

Thanks,  
Nelson Pita

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 25, 2017, 2:25pm UTC](https://discuss.elastic.co/t/elk-architecture-and-requirements/101075/6 "2017-09-25T14:25:02Z")

</div>

If you want your Elasticsearch cluster to be highly available, you need 3 nodes just for Elasticsearch. This assumes nodes that have the default configuration (master eligible, holds data and supports ingest if you need it).

Add to that nodes for Logstash and Kibana, probably 2 each if you need to separate out tiers.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2017, 2:25pm UTC](https://discuss.elastic.co/t/elk-architecture-and-requirements/101075/7 "2017-10-23T14:25:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
