# ELK cluster installation on 3 nodes + 1 node for Kibana only

**URL:** <https://discuss.elastic.co/t/elk-cluster-installation-on-3-nodes-1-node-for-kibana-only/226966>\
**Category:** Elasticsearch\
**Created:** [April 7, 2020, 5:41pm UTC](https://discuss.elastic.co/t/elk-cluster-installation-on-3-nodes-1-node-for-kibana-only/226966 "2020-04-07T17:41:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![d.silwon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/d.silwon/32/65853_2.png) [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Post date:** [April 7, 2020, 5:41pm UTC](https://discuss.elastic.co/t/elk-cluster-installation-on-3-nodes-1-node-for-kibana-only/226966/1 "2020-04-07T17:41:41Z")

</div>

Dears,

I need your help and opinions in my case.  
I've got a request for installation ELK Cluster in such configuration:  
3 x nodes for Elasticsearch, each node will be master/data/ingest node, on each node will be installed Logstash  
1 x node with installed Kibana

I'm afraid about installation Logstash on 3 nodes and his configuration. Maybe I'm wrong and this is typical or standard installation but I'm reviewed few example 3 nodes configuration and alway Lostash was installed only on 1 node.

What do you think about such idea of ELK Cluster?  
Could you tell me how to configure logstash in this case, please?

Thanks a lot

Best Regards,  
d

---

<div class="post-metadata">

**Author:** ![oneoneonepig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oneoneonepig/32/66018_2.png) [@oneoneonepig](https://discuss.elastic.co/u/oneoneonepig)\
**Post date:** [April 10, 2020, 3:35am UTC](https://discuss.elastic.co/t/elk-cluster-installation-on-3-nodes-1-node-for-kibana-only/226966/2 "2020-04-10T03:35:14Z")

</div>

Hi @d.silwon,

Where you install logstash or other log/metric collecting agents depends on what you want to collect and how you'd like to parse the data.

If your purpose is to collect logs/metrics from **all nodes** , you should have **a logstash instance installed on each node**.

If your purpose is to collect log/metric from **other agent** like filebeat or metricbeat, you can have **a single logstash instance** which receives data from filebeat, and sends data to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![d.silwon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/d.silwon/32/65853_2.png) [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Post date:** [April 10, 2020, 3:59am UTC](https://discuss.elastic.co/t/elk-cluster-installation-on-3-nodes-1-node-for-kibana-only/226966/3 "2020-04-10T03:59:53Z")

</div>

Hi @oneoneonepig ,

Our Logstash will collect log/metric from another agent like filebeat/metricbeat, from another machines.

Thank you very much.

Best Regards,  
d

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2020, 3:59am UTC](https://discuss.elastic.co/t/elk-cluster-installation-on-3-nodes-1-node-for-kibana-only/226966/4 "2020-05-08T03:59:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
