# Kibana search multiple elasticsearch instances

**URL:** <https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740>\
**Category:** Kibana\
**Created:** [October 6, 2015, 10:46pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740 "2015-10-06T22:46:41Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [October 6, 2015, 10:46pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/1 "2015-10-06T22:46:41Z")

</div>

I currently have the following environment setup with ELK.

2 elasticsearch servers  
2 logstash servers  
2 kibana servers

logstash 1 is sending to elasticsearch 1 and kibana 1 is pointing at the elasticsearch 1 server  
I have the same setup on my ELK 2 servers.

How do I get them all clustered and talking together and allow for kibana 1 and kibana 2 the ability to search elasticsearch cluster...?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 6, 2015, 10:47pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/2 "2015-10-06T22:47:19Z")

</div>

You could use a tribe node to search both clusters.

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [October 6, 2015, 10:51pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/3 "2015-10-06T22:51:33Z")

</div>

I think I understand... I have bad wording (obviously), but I want to have elasticsearch 1 and 2 clustered together and same thing for the logstash servers.

Do I need redis in front of my logstash servers?

I mainly do not know where to go next to get them all working together...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 6, 2015, 10:52pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/4 "2015-10-06T22:52:41Z")

</div>

Are the ES servers in the same place?

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [October 6, 2015, 10:55pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/5 "2015-10-06T22:55:23Z")

</div>

Same network all on individual servers.

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [October 6, 2015, 10:55pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/6 "2015-10-06T22:55:44Z")

</div>

virtual ubuntu 14.04 servers.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 7, 2015, 12:25am UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/7 "2015-10-07T00:25:23Z")

</div>

Then you can cluster those together, take a look at [https://www.elastic.co/guide/en/elasticsearch/guide/current/\_add\_failover.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/_add_failover.html)

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [October 7, 2015, 3:52pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/8 "2015-10-07T15:52:51Z")

</div>

What about Kibana? I have 2 kibana servers, to use them both to be able to search elasticsearch cluster.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 7, 2015, 7:54pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/9 "2015-10-07T19:54:48Z")

</div>

Why do you need both if you have a single cluster?

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [October 10, 2015, 2:23pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/10 "2015-10-10T14:23:29Z")

</div>

Just to confirm, you have one Elasticsearch cluster consisting of two nodes and you want to set up two Kibana instances to talk to them. In this case, you don't need a tribe node -- it's only useful to search across two separate clusters.

I can imagine two scenarios for why you might want to do this: (1) high availability; (2) separate Kibana instances for different departments. In either case, you'll want to set up an HA proxy or a load balancer that spreads requests across both Elasticsearch nodes and configure both Kibana instances to talk to that proxy or LB. In scenario (1) ensure that both Kibana instances are configured to have the same internal .kibana index, in scenario (2) ensure they have different internal indexes, e.g. .kibana-team1 and .kibana-team2.

---

<div class="post-metadata">

**Author:** ![Kaufusihm](https://avatars.discourse-cdn.com/v4/letter/k/bcef8e/32.png) [@Kaufusihm](https://discuss.elastic.co/u/Kaufusihm)\
**Post date:** [October 16, 2015, 7:28am UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/11 "2015-10-16T07:28:06Z")

</div>

I will eventually have more but just getting ready to expand. But correct, I don't need it now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:11pm UTC](https://discuss.elastic.co/t/kibana-search-multiple-elasticsearch-instances/31740/12 "2017-07-06T14:11:12Z")

</div>


