# Hardware Configuration Setup for ELK

**URL:** <https://discuss.elastic.co/t/hardware-configuration-setup-for-elk/141019>\
**Category:** Elasticsearch\
**Created:** [July 22, 2018, 6:02am UTC](https://discuss.elastic.co/t/hardware-configuration-setup-for-elk/141019 "2018-07-22T06:02:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sekharangadala](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sekharangadala](https://discuss.elastic.co/u/sekharangadala)\
**Post date:** [July 22, 2018, 6:02am UTC](https://discuss.elastic.co/t/hardware-configuration-setup-for-elk/141019/1 "2018-07-22T06:02:40Z")

</div>

Hi,

We are trying to setup ELK in production to gather all our postfix-mail logs to show in an UI for the email delivery questions.

Please let me know the hardware configuration required for the setup.

#we have 300 servers mail logs will be gathering and realtime date needs to be shown in kibana UI.

Please let me know if you need any detais from my end.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 22, 2018, 6:20am UTC](https://discuss.elastic.co/t/hardware-configuration-setup-for-elk/141019/2 "2018-07-22T06:20:18Z")

</div>

May I suggest you look at the following resources about sizing:

[https://www.elastic.co/elasticon/conf/2016/sf/quantitative-cluster-sizing](https://www.elastic.co/elasticon/conf/2016/sf/quantitative-cluster-sizing)

> **[How many shards should I have in my Elasticsearch cluster?
	  	 | Elastic](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster)**
>
> Elasticsearch is a very versatile platform, that supports a variety of use cases, and provides great flexibility around data organisation and replication strategies. This flexibility can however somet...

> **[NetSecureDay: Managing your Black Friday Logs](https://speakerdeck.com/elastic/netsecureday-managing-your-black-friday-logs)**
>
> Surveiller une application complexe n’est pas une tâche aisée, mais avec les bons outils, ce n’est pas si sorcier. Néanmoins, des périodes fortes telles que les opérations de type « Black Friday » (Vendredi noir) ou période de Noël peuvent pousser...

---

<div class="post-metadata">

**Author:** ![sekharangadala](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sekharangadala](https://discuss.elastic.co/u/sekharangadala)\
**Post date:** [July 22, 2018, 12:06pm UTC](https://discuss.elastic.co/t/hardware-configuration-setup-for-elk/141019/3 "2018-07-22T12:06:46Z")

</div>

Hi,

Thank you for your valuable suggestions on sizing. I have some queries on sizing still.  
As I mentioned earlier we have 300 servers postfix mail logs data will be pushed to logstash and the current live data of 300 mail servers will be around 1500mb data daily.

We want the postfix-mail logs data of 30days in logstash to get view of data in Kibana where how elastic search node/server should be scalable. Now my question is in what server configuration I need to look for logstash and elastic search separately?

Please suggest and help me to build a server seperately.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 22, 2018, 12:30pm UTC](https://discuss.elastic.co/t/hardware-configuration-setup-for-elk/141019/4 "2018-07-22T12:30:55Z")

</div>

I believe the links I pasted and the video would give you a lot of ideas.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2018, 12:30pm UTC](https://discuss.elastic.co/t/hardware-configuration-setup-for-elk/141019/5 "2018-08-19T12:30:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
