# Elk stack node number

**URL:** https://discuss.elastic.co/t/elk-stack-node-number/131027
**Category:** Elasticsearch
**Created:** [May 8, 2018, 2:45pm UTC](https://discuss.elastic.co/t/elk-stack-node-number/131027 "2018-05-08T14:45:27Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![mkemalm](https://avatars.discourse-cdn.com/v4/letter/m/a3d4f5/32.png) [@mkemalm](https://discuss.elastic.co/u/mkemalm)
#### Post date: [May 8, 2018, 2:45pm UTC](https://discuss.elastic.co/t/elk-stack-node-number/131027/1 "2018-05-08T14:45:27Z")

</div>

Hi,

I am curious about how can I decide number of nodes for a production elk stack cluster. My questions are below;

How can I decide;

-How many data nodes do I need? (how many of them are for hot data, how many of them for warm data?)  
-Master nodes should be at least 3, can I install them on data nodes or are seperated master nodes better?  
-I read that ingest node is only useful for log tailing functions, for more functions(metrics etc.) I should use logstash. Is it correct? How many logstash servers should I use?  
-Should I use a seperated ML node or can I mark master nodes as ML node?

Regards.

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [May 8, 2018, 3:31pm UTC](https://discuss.elastic.co/t/elk-stack-node-number/131027/2 "2018-05-08T15:31:17Z")

</div>

May I suggest you look at the following resources about sizing:

[https://www.elastic.co/elasticon/conf/2016/sf/quantitative-cluster-sizing](https://www.elastic.co/elasticon/conf/2016/sf/quantitative-cluster-sizing)

> **[How many shards should I have in my Elasticsearch cluster?
	  	 | Elastic](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster)**
>
> Elasticsearch is a very versatile platform, that supports a variety of use cases, and provides great flexibility around data organisation and replication strategies. This flexibility can however somet...

> **[NetSecureDay: Managing your Black Friday Logs](https://speakerdeck.com/elastic/netsecureday-managing-your-black-friday-logs)**
>
> Surveiller une application complexe n’est pas une tâche aisée, mais avec les bons outils, ce n’est pas si sorcier. Néanmoins, des périodes fortes telles que les opérations de type « Black Friday » (Vendredi noir) ou période de Noël peuvent pousser...

---

<div class="post-metadata">

### Author: ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)
#### Post date: [May 9, 2018, 7:13am UTC](https://discuss.elastic.co/t/elk-stack-node-number/131027/3 "2018-05-09T07:13:02Z")

</div>

this is about your data as:  
1. how many data in seconds input es;  
2. enyone the data size;  
3. how many the data fields;  
4. search respone time;  
5. the machine cpu and memory;  
6. ect...

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 6, 2018, 7:13am UTC](https://discuss.elastic.co/t/elk-stack-node-number/131027/4 "2018-06-06T07:13:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
