ELK Sizing recommendations for Log monitoring?

Calling out ELK experts to review my design.

  1. Do you recommend doubling the no. of shards from 4 to 8 for each index ?
  2. One dedicated master node (having 2TB, 256 GB and 16 CPU) will suffice the purpose for managing entire cluster or should i pull out 2 - 3 small VMs out of 5 nodes and dedicate to master node ?
  3. Do you recommend Data + ML on the same node ?
  4. Client node should be dedicated

Thanks
Vikas Mahajan

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.