# ELK Stack Architecture recommendation

**URL:** <https://discuss.elastic.co/t/elk-stack-architecture-recommendation/164894>\
**Category:** Elasticsearch\
**Created:** [January 19, 2019, 12:36pm UTC](https://discuss.elastic.co/t/elk-stack-architecture-recommendation/164894 "2019-01-19T12:36:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Amir\_Soleimani](https://avatars.discourse-cdn.com/v4/letter/a/ad7895/32.png) [@Amir\_Soleimani](https://discuss.elastic.co/u/Amir_Soleimani)\
**Post date:** [January 19, 2019, 12:36pm UTC](https://discuss.elastic.co/t/elk-stack-architecture-recommendation/164894/1 "2019-01-19T12:36:18Z")

</div>

Hello, I want to deploy Elastichsearch in a environment to collect logs from few virtual machines in a network and insert those logs in a single Elasticsearch node and visualize the data via Kibana, but I don't know how I should do it, should I run Filebeat on every VM that I want to collect logs and the Elasticsearch, Kibana and Logstash on a vm?  
or all of these module can be in a machine and Filebeat can remotely collect the logs from VMs?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 16, 2019, 12:36pm UTC](https://discuss.elastic.co/t/elk-stack-architecture-recommendation/164894/2 "2019-02-16T12:36:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
