# Is this ES config valid & how to address cluster

**URL:** <https://discuss.elastic.co/t/is-this-es-config-valid-how-to-address-cluster/315262>\
**Category:** Elasticsearch\
**Created:** [September 27, 2022, 1:12pm UTC](https://discuss.elastic.co/t/is-this-es-config-valid-how-to-address-cluster/315262 "2022-09-27T13:12:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bitdoctor](https://avatars.discourse-cdn.com/v4/letter/b/8797f3/32.png) [@Bitdoctor](https://discuss.elastic.co/u/Bitdoctor)\
**Post date:** [September 27, 2022, 1:12pm UTC](https://discuss.elastic.co/t/is-this-es-config-valid-how-to-address-cluster/315262/1 "2022-09-27T13:12:19Z")

</div>

Even though there are amazing communities like this, it's still difficult to find good answers on some things. We have 1 x Kibana, 1 x LogStash, 3 x ES Cluster nodes. Is this a valid architecture; or do we have to have 1 Logstash for each cluster node? We want to minimize overall cost by having just a single Kibana node and, if practical, a single LogStash node - Most articles i see always reference a "One-for-one" between LS --\> ES. And then, how to address the cluster - typically, you would think a single DNS name for a cluster (?) but, from most of what I've seen, this entails using load balancer/proxy or some prior-mentioned 'client front-end?' Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 30, 2022, 3:52am UTC](https://discuss.elastic.co/t/is-this-es-config-valid-how-to-address-cluster/315262/2 "2022-09-30T03:52:21Z")

</div>

> [@Bitdoctor](#):
>
> Is this a valid architecture; or do we have to have 1 Logstash for each cluster node?

This is valid. The number of Logstash nodes is not dependent on the number of Elasticsearch nodes. You can have just one, but may want to have 2 for high availability.

> [@Bitdoctor](#):
>
> Most articles i see always reference a "One-for-one" between LS --\> ES

That is not a requirement. There may be more or less Logstash nodes compared to Elasticsearch nodes. It generally depend on the number of data types being ingested and the location of these.

> [@Bitdoctor](#):
>
> how to address the cluster - typically, you would think a single DNS name for a cluster (?) but, from most of what I've seen, this entails using load balancer/proxy or some prior-mentioned 'client front-end?' Thanks in advance!

You can have a load balancer in front of Elasticsearch, but that is optional. In may deployments all Elasticsearch nodes. are listed in the Logstash outputs and this allows it to connect to all nodes and spread the load.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2022, 3:53am UTC](https://discuss.elastic.co/t/is-this-es-config-valid-how-to-address-cluster/315262/3 "2022-10-28T03:53:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
