# How to give cluster IP in fluentd/kibana for 3 node Elasticsearch cluster

**URL:** <https://discuss.elastic.co/t/how-to-give-cluster-ip-in-fluentd-kibana-for-3-node-elasticsearch-cluster/275289>\
**Category:** Elasticsearch\
**Created:** [June 8, 2021, 11:23am UTC](https://discuss.elastic.co/t/how-to-give-cluster-ip-in-fluentd-kibana-for-3-node-elasticsearch-cluster/275289 "2021-06-08T11:23:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![khgupta3](https://avatars.discourse-cdn.com/v4/letter/k/b3f665/32.png) [@khgupta3](https://discuss.elastic.co/u/khgupta3)\
**Post date:** [June 8, 2021, 11:23am UTC](https://discuss.elastic.co/t/how-to-give-cluster-ip-in-fluentd-kibana-for-3-node-elasticsearch-cluster/275289/1 "2021-06-08T11:23:21Z")

</div>

Hi All,

I have 3 node cluster (3 VM with different IPs) . After going thru some documentations and other community questions, I read that in small cluster like if 3, to have redundancy it is good to make all Master as well as Data node. So, if 1 node goes down, other 2 can vote and make Master. Question I have are for my 3 node (10.1.1.21, 10.1.1.22, 10.1.1.23)

1. What will happen if my **2 node goes down**. How I can achieve redundancy for the same?
2. Which IP I have to give in **fluentd/logstash** to receive data? Can we have some VIP or cluster name. I saw that we can give multiple IPs in "hosts" but I think it is not a good way to do. If 1 more node will be added in future, all configuration in agents needs to be changed.
3. From which IP we can run Kibana? Let's say I installed Kibana on 10.1.1.21 and in yaml file defined all 3 IPs under elasticsearch.hosts: (as per link below). But what will happen if 10.1.1.21 itself is down? How we can access it, do person has to change node manually or we can have cluster/VIP?  
[Use Kibana in a production environment | Kibana Guide [7.13] | Elastic](https://www.elastic.co/guide/en/kibana/current/production.html)

I also read about voting exclusion but not sure if my 2 node goes down, how we can still continue to receive the data with 1 node. Or is there any way to achieve it?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 8, 2021, 12:01pm UTC](https://discuss.elastic.co/t/how-to-give-cluster-ip-in-fluentd-kibana-for-3-node-elasticsearch-cluster/275289/2 "2021-06-08T12:01:39Z")

</div>

> [@khgupta3](#):
>
> What will happen if my **2 node goes down**. How I can achieve redundancy for the same?

An Elasticsearch cluster always require a strict majority of master-eligible nodes to be available in order to be fully functional. This means that you can only afford to lose 1 node in a 3 node cluster.

> [@khgupta3](#):
>
> I saw that we can give multiple IPs in "hosts" but I think it is not a good way to do.

This is a good way to do it. If the process sending data to Elasticsearch supports sniffing you can use that to discover new nodes.

> [@khgupta3](#):
>
> But what will happen if 10.1.1.21 itself is down?

If you want Kibana to be highly available you need it installed on multiple nodes and allow it to connect to multiple nodes in the cluster.

> [@khgupta3](#):
>
> I also read about voting exclusion but not sure if my 2 node goes down, how we can still continue to receive the data with 1 node. Or is there any way to achieve it?

No.

---

<div class="post-metadata">

**Author:** ![khgupta3](https://avatars.discourse-cdn.com/v4/letter/k/b3f665/32.png) [@khgupta3](https://discuss.elastic.co/u/khgupta3)\
**Post date:** [June 8, 2021, 12:20pm UTC](https://discuss.elastic.co/t/how-to-give-cluster-ip-in-fluentd-kibana-for-3-node-elasticsearch-cluster/275289/3 "2021-06-08T12:20:05Z")

</div>

Thanks Christian for your prompt reply.

But installing Kibana too on all 3 nodes, will require people to change IP while accessing it. However, it should happen automatically if we give any Cluster IP or cluster name where IP at backend can change according to availability.

Same goes for fluentd/logstash. To give single virtual IP and on backend it should send data to the avaialble node.

How we can achieve the same?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 8, 2021, 12:30pm UTC](https://discuss.elastic.co/t/how-to-give-cluster-ip-in-fluentd-kibana-for-3-node-elasticsearch-cluster/275289/4 "2021-06-08T12:30:33Z")

</div>

I think you either need a load balancer or to work with DNS.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 8, 2021, 2:19pm UTC](https://discuss.elastic.co/t/how-to-give-cluster-ip-in-fluentd-kibana-for-3-node-elasticsearch-cluster/275289/5 "2021-06-08T14:19:57Z")

</div>

What are you using to ship data to elasticsearch? fluentd and logstash? Or you use fluentd to ship to logstash and then to elasticsearch?

In logstash you can use a environment variable with the hosts and use that variable in the elasticsearch output of your pipeline.

Something like this:

```auto
output {
  elasticsearch {
    hosts => ["${ES_HOSTS}"]
  }
}

```

Then you need to create an environment variable with the following format:

```auto
ES_HOSTS="https://es-node-01:9200 https://es-node-02:9200 https://es-nodeN:9200"

```

You can create this in the environment of the user running logstash, in the file `/etc/sysconfig/logstash` or use a [logstash keystore](https://www.elastic.co/guide/en/logstash/current/keystore.html).

I currently use the file `/etc/sysconfig/logstash` for my logstash variables, the logstash keystore is a good choice too, but you can't automate it as it does not support stdin inputs with spaces when creating keys. In any case, you would need to restart logstash to refresh the variables.

For Kibana, if you have three Kibana instances you could use a VIP IP or a load balancer, you can create a VIP IP easy using keepalived or you can try to use nginx or haproxy as load balancer.

---

<div class="post-metadata">

**Author:** ![khgupta3](https://avatars.discourse-cdn.com/v4/letter/k/b3f665/32.png) [@khgupta3](https://discuss.elastic.co/u/khgupta3)\
**Post date:** [June 9, 2021, 5:13am UTC](https://discuss.elastic.co/t/how-to-give-cluster-ip-in-fluentd-kibana-for-3-node-elasticsearch-cluster/275289/6 "2021-06-09T05:13:13Z")

</div>

Thanks Leandro.

I am using fluentd to sent data to Elasticsearch directly. But if I give just 1 IP and that server got down then all write operations will be stopped. So, I was checking some option to give Cluster name here or some cluster IP, which automatically detect the running server and start sending it's data to that.

Replica of shards will then be made to other 2 nodes.

\<match swift.\*\*\>  
@type copy  
  
@type elasticsearch  
host 10.1.1.21  
port 9200  
include\_tag\_key true  
tag\_key @log\_name  
logstash\_format true  
include\_timestamp true  
flush\_interval 10s  
reconnect\_on\_error true  
reload\_on\_failure true  
reload\_connections false

For Kibana, let me try by making VIP and installing Kibana on all 3 nodes. So, you recommend in Kibana.yml, hosts I have to define respective locahost:9090 (elasticsearch) or all 3 hosts of ES in all instances of Kibana?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2021, 5:13am UTC](https://discuss.elastic.co/t/how-to-give-cluster-ip-in-fluentd-kibana-for-3-node-elasticsearch-cluster/275289/7 "2021-07-07T05:13:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
