# ELK clustering

**URL:** <https://discuss.elastic.co/t/elk-clustering/172064>\
**Category:** Beats\
**Created:** [March 13, 2019, 5:50am UTC](https://discuss.elastic.co/t/elk-clustering/172064 "2019-03-13T05:50:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cppatel](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@cppatel](https://discuss.elastic.co/u/cppatel)\
**Post date:** [March 13, 2019, 5:50am UTC](https://discuss.elastic.co/t/elk-clustering/172064/1 "2019-03-13T05:50:41Z")

</div>

We are going to do clustering of ELK nodes. So the idea is to run whole ELK on 1 node as well as on the second node too with same configuration of ELK. But we want to make a second node as a standby node ( file beat should send the data to the second node whenever the first node is unreachable to it). Is it possible to do so? Please provide me a related document.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 13, 2019, 2:25pm UTC](https://discuss.elastic.co/t/elk-clustering/172064/2 "2019-03-13T14:25:27Z")

</div>

Filebeat does not differntiate between cluster.

You sending to Logstash?

Why not rely on Elasticsearch clusters for HA and reliability?

Have you consider [cross cluster replication](https://www.elastic.co/guide/en/elastic-stack-overview/current/xpack-ccr.html) ?

---

<div class="post-metadata">

**Author:** ![cppatel](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@cppatel](https://discuss.elastic.co/u/cppatel)\
**Post date:** [March 14, 2019, 7:30am UTC](https://discuss.elastic.co/t/elk-clustering/172064/3 "2019-03-14T07:30:13Z")

</div>

> [@steffens](#):
>
> Filebeat does not differntiate between cluster.

I don't want it to do differentiate between cluster. I want that if it can make a difference between 2 ELK nodes. So, if primary node is down then filebeat can learn that it has to send a data to the secondary node and I could be able to access that kibana URL which will run from secondary node.

---

<div class="post-metadata">

**Author:** ![cppatel](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@cppatel](https://discuss.elastic.co/u/cppatel)\
**Post date:** [March 14, 2019, 7:31am UTC](https://discuss.elastic.co/t/elk-clustering/172064/4 "2019-03-14T07:31:00Z")

</div>

> [@steffens](#):
>
> You sending to Logstash?

yes I am sending it to logstash.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 14, 2019, 2:24pm UTC](https://discuss.elastic.co/t/elk-clustering/172064/5 "2019-03-14T14:24:13Z")

</div>

> > Filebeat does not differntiate between cluster.
> 
> I don't want it to do differentiate between cluster. I want that if it can make a difference between 2 ELK nodes.

One configures the Logstash endpoints/Nodes with Beats. But Beats assumes that all configured nodes/endpoints belong to the same cluster.  
One can run Beats in `failover` mode (set `output.logstash.loadbalance: false`). In this case Beats will publish to one logstash Node only. But which node is chosen is totally at random.

Why do you need separate clusters each containing ES and logstash, and Kibana? Why not one ES cluster and a fleet of Logstash instances, that Beats will publish too?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2019, 4:24pm UTC](https://discuss.elastic.co/t/elk-clustering/172064/6 "2019-04-11T16:24:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
