Sorry if I am asking this question in wrong group. I have Archsight CEF data which I will be ingesting into ES using LS . To achieve HA I have total 8 machines 2-ES, 2-LS(these also have syslog-ng), 2-Kibana and 2-Nginx(for reverse proxy and load balance).
Now, In the above architecture I am not able to distribute traffic equally between two syslog-ng/LS machines in round-robin method from Nginx. So below is what I want to achieve
CEF DATA -> NGINX INSTANCE ----REDIRECT(load balance) ---> syslog-SERVER 1(LS1) AND syslog-SERVER 2 (LS2).
In order to operate properly, Elasticsearch need an elected master node in the cluster. If this is not available the cluster is not able to accept writes as this could lead to data loss. Masters are elected by a majority of master eligible nodes, which means that you will need at least 3 Elasticsearch nodes in order to achieve HA.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.