I have a cluster of 4 master, 8 data and 2 client/query nodes. This is ingesting logs from logstash. Currently, logstash is sending to all the data nodes (assumption: its load balancing). Is this the most optimal way? Should logstash send to the client/query nodes instead? Currently, the client nodes are what Kibana and Grafana speak to and have the most RAM and cores provisioned for it.
Thanks in advance for any pointers.