# Graylog vs elasticsearch capacity planning

**URL:** <https://discuss.elastic.co/t/graylog-vs-elasticsearch-capacity-planning/86056>\
**Category:** Elasticsearch\
**Created:** [May 17, 2017, 7:21am UTC](https://discuss.elastic.co/t/graylog-vs-elasticsearch-capacity-planning/86056 "2017-05-17T07:21:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kekou](https://avatars.discourse-cdn.com/v4/letter/k/779978/32.png) [@kekou](https://discuss.elastic.co/u/kekou)\
**Post date:** [May 17, 2017, 7:21am UTC](https://discuss.elastic.co/t/graylog-vs-elasticsearch-capacity-planning/86056/1 "2017-05-17T07:21:16Z")

</div>

Hi,

I'm new to elasticsearch :).

i'm actually planning to deploy a graylog instance for managing about 100GB / day of log and keep them for a year, so a total of 36/40TB of Log (~5000 msg/s).  
The main usage of the solution will be to index log everyday, with some dashboards and smarts alerts on the last 24h.  
The other usage by 2 or 3 peoples search over multiple week of log.

So i don't really need High availability (graylog server have some cache to handle elastic unavailability), i only need to index and access a big amount of data.

Is it possible to get a signle elastic search big server bi-18core 253MB ram and 50TB of storage?  
My goal is to simplify maintenance and limit price of solution.

Thanks  
Lionel

---

<div class="post-metadata">

**Author:** ![rusty](https://avatars.discourse-cdn.com/v4/letter/r/f17d59/32.png) [@rusty](https://discuss.elastic.co/u/rusty)\
**Post date:** [May 17, 2017, 7:47am UTC](https://discuss.elastic.co/t/graylog-vs-elasticsearch-capacity-planning/86056/2 "2017-05-17T07:47:49Z")

</div>

Hello! It's possible, but ES has some "hidden" limitations. For my setup one ES instance (HEAP 31GB) can handle 5-6TB of indexed data (it's almost eated by terms\_in\_memory and other internal stuff). So you should start 5-6 ES instances in one server to handle 30-40TB of indexed data. You'd better test on real data and see if you affected or not. Another caveat is you'll get one single point of failure (replicas on one server is useless) so better use 3-4 middle servers to get more stability.

---

<div class="post-metadata">

**Author:** ![kekou](https://avatars.discourse-cdn.com/v4/letter/k/779978/32.png) [@kekou](https://discuss.elastic.co/u/kekou)\
**Post date:** [May 17, 2017, 8:02am UTC](https://discuss.elastic.co/t/graylog-vs-elasticsearch-capacity-planning/86056/3 "2017-05-17T08:02:47Z")

</div>

Ok thanks for your response, perhaps i can transform my big server into hypervisor and get 5-6 VM (instance of standalone ES server).

---

<div class="post-metadata">

**Author:** ![rusty](https://avatars.discourse-cdn.com/v4/letter/r/f17d59/32.png) [@rusty](https://discuss.elastic.co/u/rusty)\
**Post date:** [May 17, 2017, 8:15am UTC](https://discuss.elastic.co/t/graylog-vs-elasticsearch-capacity-planning/86056/4 "2017-05-17T08:15:49Z")

</div>

For HA it's better to use different h/w boxes or cloud VMs. If you have one server it's easier to use docker or start multiple ES on different ports (see [link](https://discuss.elastic.co/t/can-i-run-multiple-elasticsearch-nodes-on-the-same-machine/67?u=rusty)).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2017, 8:15am UTC](https://discuss.elastic.co/t/graylog-vs-elasticsearch-capacity-planning/86056/5 "2017-06-14T08:15:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
