# ELK CCR Setup

**URL:** <https://discuss.elastic.co/t/elk-ccr-setup/324719>\
**Category:** Elasticsearch\
**Tags:** ccr-cross-cluster-replication\
**Created:** [February 4, 2023, 10:54pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719 "2023-02-04T22:54:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Post date:** [February 4, 2023, 10:54pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719/1 "2023-02-04T22:54:38Z")

</div>

Hello,

I want to test the CCR feature, and I understand these two limitations exist:

1. A follower can only follow one leader.
2. No way to directly write events from the client side to the follower index.

with these two limitations, whether the setup is Active-Standby or Active-Active, there must be some events dropped in case of outage because the leader in the active region is down, and the follower in the passive region cannot be written to.  
(I am using both time-based indices and non-time-based indices and document updates are happening).

Is there any way to prevent this from happening instead of manually switching the active and standby indices? The availability aspect is important for our use case so we want to make sure we don't lose any events as much as we can in case of outage in a region.

Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 4, 2023, 11:11pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719/2 "2023-02-04T23:11:09Z")

</div>

Hi @mostafaelsayed

Take a look at [this](https://www.elastic.co/blog/bi-directional-replication-with-elasticsearch-cross-cluster-replication-ccr) it is a little dated but concepts still apply.

Basically, you have a leader/follower on both sides...

Each Side write to its leader

Each side Read from a Data view that reads both leader and follower...

These two images shows the concept

Write Alias always writes to leader

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/5/651a373ddaa81c3451e31f9a2ada89eb2df943c5.png)

Read Alias always reads from both

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/6/061a594b3d2b3c45ba1a170e2defcdc69c14b14a.png)

So Imagine dc1 goes down you just switch the inbound traffic to the write alias in DC2...

This can work in the Active Standby... When Active goes down then you write to the write alias in the Standby... and read from both.

Obviously, there are details and different implementations and you could use a load balance with a health check etc... but that is the basic concept.

BTW this is not without some additional work, Elastic provides building blocks for these types of operations but it is not native out of the box, I am hoping we make this simpler for our users in the future.

---

<div class="post-metadata">

**Author:** ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Post date:** [February 4, 2023, 11:47pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719/3 "2023-02-04T23:47:06Z")

</div>

Hi @stephenb

Thanks. But the problem is that the application is doing document updates so this setup still won't work for this case.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 4, 2023, 11:51pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719/4 "2023-02-04T23:51:17Z")

</div>

Hi @mostafaelsayed

Yes as the article says this does not support updates, apologies, your post said write not update I made a poor assumption.

Bidirectional updates are not supported.

Instant failover of write/update to a follower index is not supported.

Neither of these is supported as far as I understand at this time, it takes time to "unfollow" a leader and then it can not be turned back into a follower again.

The users/customer that I work with that have such stringent requirements use a queuing technology like Kafka to support these types of requirements

---

<div class="post-metadata">

**Author:** ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Post date:** [February 5, 2023, 12:24am UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719/5 "2023-02-05T00:24:17Z")

</div>

Thanks @stephenb I will check out the Kafka option

---

<div class="post-metadata">

**Author:** ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Post date:** [February 16, 2023, 6:23pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719/6 "2023-02-16T18:23:23Z")

</div>

Hello @stephenb

I want to confirm something please.

the following image from the docs suggests that a follower can follow more than one leader which I think this is a limitation and can't happen, right?

Is this true that one follower can follow multiple leaders, or the image is assuming that no updates happen, and this one follower is in fact multiple followers, one for each leader?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d32ae1559aad3eae7f5afb588e486de02a58223e.png)

Thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 16, 2023, 6:26pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719/7 "2023-02-16T18:26:29Z")

</div>

I believe the diagram assumes you have one index per region and that the follower is replicating these 3 indices (different names) into the central reporting cluster.

---

<div class="post-metadata">

**Author:** ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Post date:** [February 16, 2023, 6:36pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719/8 "2023-02-16T18:36:00Z")

</div>

Thank you @Christian_Dahlqvist I believe that too, I just wanted to confirm.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2023, 6:36pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719/9 "2023-03-16T18:36:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
