# Elk cluster plan with 7000EPS an 100/s search

**URL:** https://discuss.elastic.co/t/elk-cluster-plan-with-7000eps-an-100-s-search/21286
**Category:** Elasticsearch
**Created:** [December 17, 2014, 3:46am UTC](https://discuss.elastic.co/t/elk-cluster-plan-with-7000eps-an-100-s-search/21286 "2014-12-17T03:46:06Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![limac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/limac/32/3981_2.png) [@limac](https://discuss.elastic.co/u/limac)
#### Post date: [December 17, 2014, 3:46am UTC](https://discuss.elastic.co/t/elk-cluster-plan-with-7000eps-an-100-s-search/21286/1 "2014-12-17T03:46:06Z")

</div>

Hi folks,

I am building an elk cluster to index and search lots of http access log,  
about more than 7000Event per second and also there will be more than 100  
cocurrent searchs.

I have 2 machines. One of them has 24 cpu cores, 64G memory and 2T sata  
disk(no raid). The other one is much powerful, which has 24 core cpu, 384G  
memory and 300G sas disk\*8.

My plan is to build a 3-node elasticsearch, one running on small server, the  
other two running on the big one. Can I route all index request to one node  
while all search request to the other two nodes? Is this a good idea to do  
like this? Any comments?

Thank you guys and happy holiday!

Alan

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/000801d019ac%2400659130%240130b390%24%40gmail.com](https://groups.google.com/d/msgid/elasticsearch/000801d019ac%2400659130%240130b390%24%40gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)
#### Post date: [December 17, 2014, 8:34am UTC](https://discuss.elastic.co/t/elk-cluster-plan-with-7000eps-an-100-s-search/21286/2 "2014-12-17T08:34:27Z")

</div>

Just a note: if you have a machine where 24 cores must handle six times the  
RAM than another machine, it is not more powerful, it is less powerful.

You should really use machines with exact same hardware specs for ease of  
node deployment, data distribution, maintenance times, and scalability.

Jörg

On Wed, Dec 17, 2014 at 4:46 AM, Wang Yong [cnwangyong@gmail.com](mailto:cnwangyong@gmail.com) wrote:

> Hi folks,
> 
> I am building an elk cluster to index and search lots of http access log,  
> about more than 7000Event per second and also there will be more than 100  
> cocurrent searchs.
> 
> I have 2 machines. One of them has 24 cpu cores, 64G memory and 2T sata  
> disk(no raid). The other one is much powerful, which has 24 core cpu, 384G  
> memory and 300G sas disk\*8.
> 
> My plan is to build a 3-node elasticsearch, one running on small server,  
> the other two running on the big one. Can I route all index request to one  
> node while all search request to the other two nodes? Is this a good idea  
> to do like this? Any comments?
> 
> Thank you guys and happy holiday!
> 
> Alan
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/000801d019ac%2400659130%240130b390%24%40gmail.com](https://groups.google.com/d/msgid/elasticsearch/000801d019ac%2400659130%240130b390%24%40gmail.com)  
> [https://groups.google.com/d/msgid/elasticsearch/000801d019ac%2400659130%240130b390%24%40gmail.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/000801d019ac%2400659130%240130b390%24%40gmail.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAKdsXoH6TtbnXWf-m0ihYP%2BAcNN%2BCfbV2g1O%2Ba2S07bR%2BNiUOQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAKdsXoH6TtbnXWf-m0ihYP%2BAcNN%2BCfbV2g1O%2Ba2S07bR%2BNiUOQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 12:43am UTC](https://discuss.elastic.co/t/elk-cluster-plan-with-7000eps-an-100-s-search/21286/3 "2017-07-06T00:43:19Z")

</div>


