# Ingest vs Data

**URL:** <https://discuss.elastic.co/t/ingest-vs-data/299662>\
**Category:** Elasticsearch\
**Created:** [March 14, 2022, 8:03pm UTC](https://discuss.elastic.co/t/ingest-vs-data/299662 "2022-03-14T20:03:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tim\_Mobley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_mobley/32/94741_2.png) [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Post date:** [March 14, 2022, 8:03pm UTC](https://discuss.elastic.co/t/ingest-vs-data/299662/1 "2022-03-14T20:03:20Z")

</div>

I have read the [Node Roles](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html#node-roles) documentation, but am still unclear on the difference between the `ingest` and `data` roles. In particular, if a node has the `data` role but not the `ingest` role, does that mean that incoming data (e.g., from a Logstash pipeline) will not be written to that node? I'm asking because I have a situation where I want to temporarily stop incoming data to a hot data node (which currently has _both_ ingest and data roles), but I still want to be able to work with the data on that node. How best do I achieve this?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 15, 2022, 12:52am UTC](https://discuss.elastic.co/t/ingest-vs-data/299662/2 "2022-03-15T00:52:01Z")

</div>

The `ingest` role means that the node is able to run elasticsearch [ingest pipelines processors](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html) to change or enrich the data before indexing it in one or more `data` nodes.

> Ingest nodes can execute pre-processing pipelines, composed of one or more ingest processors. Depending on the type of operations performed by the ingest processors and the required resources, it may make sense to have dedicated ingest nodes, that will only perform this specific task.

If you remove the `ingest` role from the node that currently is both a `data` and `ingest` node, you will still be able to work with the data on that node, and add more data if needed, the change will be that after you remove the `ingest` role, the node will note be able to run ingest pipeline processors.

The `ingest` role name is related only to the ability to execute [ingest pipeline processors](https://www.elastic.co/guide/en/elasticsearch/reference/current/processors.html).

---

<div class="post-metadata">

**Author:** ![Tim\_Mobley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_mobley/32/94741_2.png) [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Post date:** [March 15, 2022, 5:00pm UTC](https://discuss.elastic.co/t/ingest-vs-data/299662/3 "2022-03-15T17:00:05Z")

</div>

Thank you for the info! If I may ask one follow-up regarding my particular challenge: how do I (or can I) leave a hot data node joined to the cluster, but stop it from receiving new data - while at the same time re-allocating data from that "stopped" node to others? My objective is to get all the data off these nodes. I was hoping I could do this by removing the `ingest` role, but from your response, that doesn't seem like the solution.

---

<div class="post-metadata">

**Author:** ![vincenbr](https://avatars.discourse-cdn.com/v4/letter/v/8edcca/32.png) [@vincenbr](https://discuss.elastic.co/u/vincenbr)\
**Post date:** [March 16, 2022, 3:57pm UTC](https://discuss.elastic.co/t/ingest-vs-data/299662/4 "2022-03-16T15:57:55Z")

</div>

Hi Tim, if you want to decommission one specific node, leaving it inside the cluster, you can use this command (with the proper IP addess) :

```auto
PUT _cluster/settings
{
  "persistent" : {
    "cluster.routing.allocation.exclude._ip" : "10.0.0.1"
  }
}

```

This is a dynamic setting (you can run it anytime, it is taken into account quickly). To revert (enable again this node), put the setting value to `null`  
More details in: [Cluster-level shard allocation and routing settings | Elasticsearch Guide [8.1] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-cluster.html#cluster-shard-allocation-filtering)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2022, 3:58pm UTC](https://discuss.elastic.co/t/ingest-vs-data/299662/5 "2022-04-13T15:58:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
