I'm looking to confiugre an ELK stack using the following seperated VM's for cost and scaling in a CSP.
Lselk.gtld. (Logstash)
Melk.gtld. (Master)
Ielk.gtld. (Ingest)
Delk.gtld (hot_data)
Wdelk.gtld (warm_data)
Kelk.gtld (kibana for ELK)
I'm hoping to publish a How-To on how to do this. However there's very little in the way of going about this beyond installing ELK on every node. My primary considerations are the Scaling of the Hot_Data for Elastic and Warm_Data nodes as well as making sure the Kibana is geared for heavy use.