# How to keep Shards geographically bound

**URL:** <https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209>\
**Category:** Elasticsearch\
**Created:** [May 2, 2017, 6:48am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209 "2017-05-02T06:48:07Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Simon\_Oxwell](https://avatars.discourse-cdn.com/v4/letter/s/f17d59/32.png) [@Simon\_Oxwell](https://discuss.elastic.co/u/Simon_Oxwell)\
**Post date:** [May 2, 2017, 6:48am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/1 "2017-05-02T06:48:07Z")

</div>

Hi,

I've got an Elasticsearch 5.3 cluster that I essentially want to store logs in for archival and search purposes, made up of two nodes, each in a different data centre. I would like to be able to search both nodes from one Kibana instance (hence the cluster), but not ship the logs between the data centres.

So far, I've been able to disable replicas, but haven't been able to figure out the right settings to stop my shards from being distributed across the cluster. I've been looking at the cluster.routing.allocation.require.\* directives, but haven't had much luck.

Thanks,  
Simon

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 2, 2017, 6:52am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/2 "2017-05-02T06:52:15Z")

</div>

> [@Simon\_Oxwell](#):
>
> I've got an Elasticsearch 5.3 cluster that I essentially want to store logs in for archival and search purposes, made up of two nodes, each in a different data centre

We don't recommend that, ES is latency sensitive.

---

<div class="post-metadata">

**Author:** ![Simon\_Oxwell](https://avatars.discourse-cdn.com/v4/letter/s/f17d59/32.png) [@Simon\_Oxwell](https://discuss.elastic.co/u/Simon_Oxwell)\
**Post date:** [May 2, 2017, 7:07am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/3 "2017-05-02T07:07:17Z")

</div>

Hmm. Sites are \<10ms apart, according to ping, but I acknowledge that might be an issue.

Can you suggest an alternative architecture? Kibana doesn't seem to be able to query more than one elasticsearch (which, to be honest I'm not expecting it to be able to), and I'm looking to not having to shovel raw log files between sites if I can help it.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 2, 2017, 7:55am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/4 "2017-05-02T07:55:53Z")

</div>

Have you looked at allocation awareness as opposed to routing?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 2, 2017, 8:02am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/5 "2017-05-02T08:02:19Z")

</div>

You can set the nodes up as separate clusters and use a tribe node to query them. This allows you to keep the data locally, but adds complexity.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 2, 2017, 8:20am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/6 "2017-05-02T08:20:36Z")

</div>

Cross cluster search would be better - [https://www.elastic.co/blog/tribe-nodes-and-cross-cluster-search-the-future-of-federated-search-in-elasticsearch](https://www.elastic.co/blog/tribe-nodes-and-cross-cluster-search-the-future-of-federated-search-in-elasticsearch)

---

<div class="post-metadata">

**Author:** ![Simon\_Oxwell](https://avatars.discourse-cdn.com/v4/letter/s/f17d59/32.png) [@Simon\_Oxwell](https://discuss.elastic.co/u/Simon_Oxwell)\
**Post date:** [May 3, 2017, 4:47am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/7 "2017-05-03T04:47:09Z")

</div>

I've looked at allocation awareness (this: [https://www.elastic.co/guide/en/elasticsearch/reference/current/allocation-awareness.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/allocation-awareness.html) ) and it seems to be about keeping replica shards outside of the 'awareness zone' that the primary shards reside in, rather than allocating all the primary shards for an index on the same cluster node where the data is ingested.

---

<div class="post-metadata">

**Author:** ![Simon\_Oxwell](https://avatars.discourse-cdn.com/v4/letter/s/f17d59/32.png) [@Simon\_Oxwell](https://discuss.elastic.co/u/Simon_Oxwell)\
**Post date:** [May 3, 2017, 4:50am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/8 "2017-05-03T04:50:07Z")

</div>

Cross-cluster search seemed to be just the thing, but Kibana doesn't support it yet ☹

> <https://github.com/elastic/kibana/issues/11011>

So that leaves a tribe node, or just wait for the next Kibana release.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 3, 2017, 5:12am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/9 "2017-05-03T05:12:01Z")

</div>

> [@Simon\_Oxwell](#):
>
> allocating all the primary shards for an index on the same cluster node where the data is ingested

You can't do that unless you manually route all the shards and then disable re-allocation.

---

<div class="post-metadata">

**Author:** ![Simon\_Oxwell](https://avatars.discourse-cdn.com/v4/letter/s/f17d59/32.png) [@Simon\_Oxwell](https://discuss.elastic.co/u/Simon_Oxwell)\
**Post date:** [May 3, 2017, 6:04am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/10 "2017-05-03T06:04:44Z")

</div>

> [@warkolm](#):
>
> You can't do that unless you manually route all the shards and then disable re-allocation.

Given that's likely to still leave me with a cluster latency issue, I think to best achieve my goal is to stop trying to fight elasticsearch, create two separate nodes for my data, and use Kibana and a tribe node to knit them together until Kibana supports cross-cluster search.

Thanks for your help, and happy forum birthday.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 3, 2017, 6:05am UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/11 "2017-05-03T06:05:54Z")

</div>

5.4 isn't far off 😉

---

<div class="post-metadata">

**Author:** ![fortikeco](https://avatars.discourse-cdn.com/v4/letter/f/a587f6/32.png) [@fortikeco](https://discuss.elastic.co/u/fortikeco)\
**Post date:** [May 5, 2017, 3:13pm UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/12 "2017-05-05T15:13:59Z")

</div>

you could set 1 shard and 0 recplicas per index (so you effectively have only 1 primary shard).  
However, you loose parallel processing and you can only store 2 billion documents per index in this configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 2, 2017, 3:17pm UTC](https://discuss.elastic.co/t/how-to-keep-shards-geographically-bound/84209/13 "2017-06-02T15:17:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
