# ES best practices?

**URL:** <https://discuss.elastic.co/t/es-best-practices/2226>\
**Category:** Elasticsearch\
**Created:** [June 9, 2015, 2:39pm UTC](https://discuss.elastic.co/t/es-best-practices/2226 "2015-06-09T14:39:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![saif](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saif/32/37431_2.png) [@saif](https://discuss.elastic.co/u/saif)\
**Post date:** [June 9, 2015, 2:39pm UTC](https://discuss.elastic.co/t/es-best-practices/2226/1 "2015-06-09T14:39:16Z")

</div>

hello

I used recently ElasticSearch I have 4 servers  
and wanted to know the good pratice  
how many:  
node-master  
node-data  
how minimum\_master\_nodes: 4/2 + 1 = 3?  
number\_of\_shards  
number\_of\_replicas

because I work with a large number of log server .. almost 3000  
so I have a lot of data .. 20G per day at least  
I use the RAID-0

thank you

---

<div class="post-metadata">

**Author:** ![mosiddi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mosiddi/32/577_2.png) [@mosiddi](https://discuss.elastic.co/u/mosiddi)\
**Post date:** [June 9, 2015, 4:05pm UTC](https://discuss.elastic.co/t/es-best-practices/2226/2 "2015-06-09T16:05:34Z")

</div>

how ur search pattern is going to look like? How much would u retain data and till when? How much documents per second u would expect coming to ur ES? the idle shard/replica, index, etc. depend a lot on ur scenario than general practice.

---

<div class="post-metadata">

**Author:** ![saif](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saif/32/37431_2.png) [@saif](https://discuss.elastic.co/u/saif)\
**Post date:** [June 10, 2015, 7:21am UTC](https://discuss.elastic.co/t/es-best-practices/2226/3 "2015-06-10T07:21:43Z")

</div>

thank you for your reply  
I used to centralize logs with ELK for 3000 servers  
it's 9 pm and I have only 1800 servers connects and i have 4,132,830 docs

just for testing i used 2 servers 2 master nodes 5 shared

![](https://us1.discourse-cdn.com/elastic/original/1X/12f738b5f1268955cd13512240739fb125dce502.png)

thank you

---

<div class="post-metadata">

**Author:** ![mosiddi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mosiddi/32/577_2.png) [@mosiddi](https://discuss.elastic.co/u/mosiddi)\
**Post date:** [June 10, 2015, 8:22am UTC](https://discuss.elastic.co/t/es-best-practices/2226/4 "2015-06-10T08:22:43Z")

</div>

Couple of general guidelines we follow -

1. Minimum 3 master nodes to avoid split-brain
2. We need HA (high-availability) and in our configuration, we leverage 2 replicas for the same
3. Too less and too much shards - Both are bad. You have to select decent number. We have multiple indices and each index have 10 primaries. We cap the data going to each index using some parameters so that they are manageable.
4. We have 3 query nodes basically to support HA, load balancing and fault-tolerance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:08am UTC](https://discuss.elastic.co/t/es-best-practices/2226/5 "2017-07-06T00:08:39Z")

</div>


