# How to solve ELK bottlenecks

**URL:** <https://discuss.elastic.co/t/how-to-solve-elk-bottlenecks/261879>\
**Category:** Logstash\
**Created:** [January 22, 2021, 7:41am UTC](https://discuss.elastic.co/t/how-to-solve-elk-bottlenecks/261879 "2021-01-22T07:41:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jang](https://avatars.discourse-cdn.com/v4/letter/j/ecb155/32.png) [@jang](https://discuss.elastic.co/u/jang)\
**Post date:** [January 22, 2021, 7:41am UTC](https://discuss.elastic.co/t/how-to-solve-elk-bottlenecks/261879/1 "2021-01-22T07:41:41Z")

</div>

I am using pipeline that uses filebeat, kafka, logstash, and Elastic service.

kafka and logstash consist of one server.(4core, 4GB ram)

Elastic service uses one master node and three data nodes.(2core, 2GB ram)

Recently, the amount of logs collected through filebeat has increased rapidly, which seems to have caused a bottleneck in the process of being stored in the Elastic service.

Please advise whether to increase the number of servers in logstash or the number of data nodes in Elastic service.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2021, 7:41am UTC](https://discuss.elastic.co/t/how-to-solve-elk-bottlenecks/261879/2 "2021-02-19T07:41:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
