# Logstash best practice

**URL:** <https://discuss.elastic.co/t/logstash-best-practice/85425>\
**Category:** Logstash\
**Created:** [May 11, 2017, 2:36pm UTC](https://discuss.elastic.co/t/logstash-best-practice/85425 "2017-05-11T14:36:17Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)\
**Post date:** [May 11, 2017, 2:36pm UTC](https://discuss.elastic.co/t/logstash-best-practice/85425/1 "2017-05-11T14:36:18Z")

</div>

Hi,  
we have a 5 nodes elasticsearch cluster running 5.2.0,  
2 of the nodes are configured as client nodes (data=false, master=false),  
3 nodes are elasticsearch cluster (data=true, master=true)

We want to install also logstash

What is the best practice for this topology?

Install the logstash at the 2 client nodes?

Install the logstash in new client server? - if so, what will happen if the node will fall? no logs will be written to elasticsearch?

Thanks,  
Talia

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 11, 2017, 2:38pm UTC](https://discuss.elastic.co/t/logstash-best-practice/85425/2 "2017-05-11T14:38:13Z")

</div>

What kind of inputs will your Logstash instance(s) have? What's the approximate event rate?

---

<div class="post-metadata">

**Author:** ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)\
**Post date:** [May 11, 2017, 2:58pm UTC](https://discuss.elastic.co/t/logstash-best-practice/85425/3 "2017-05-11T14:58:51Z")

</div>

It will get a networking logs from switches from about 1000 machines  
For about 300,000 events per half an hour

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 11, 2017, 5:41pm UTC](https://discuss.elastic.co/t/logstash-best-practice/85425/4 "2017-05-11T17:41:25Z")

</div>

Okay, so a couple of hundred events per second. A single Logstash instance would have no problems coping with that. TCP or UDP? What load balancing options are available to you?

In general it doesn't matter so much where you install Logstash. Are you sure you need two client nodes? My hunch is that you'll be better off putting the money into more powerful data nodes.

---

<div class="post-metadata">

**Author:** ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)\
**Post date:** [May 14, 2017, 6:52am UTC](https://discuss.elastic.co/t/logstash-best-practice/85425/5 "2017-05-14T06:52:40Z")

</div>

TCP

So, if I will install the logstash at the 2 clients server it will work fine?

Another question, if I can,  
How to I configure the elasticsearch to keep onle one mounth data?

Thanks a lot

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 15, 2017, 5:17am UTC](https://discuss.elastic.co/t/logstash-best-practice/85425/6 "2017-05-15T05:17:24Z")

</div>

> So, if I will install the logstash at the 2 clients server it will work fine?

Sure, but it's not clear to me how you'll utilize both servers (hence my question about load balancing). As opposed to Elasticsearch, Logstash instance don't form clusters.

> How to I configure the elasticsearch to keep onle one mounth data?

Look into Elastic Curator.

---

<div class="post-metadata">

**Author:** ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)\
**Post date:** [May 15, 2017, 7:06am UTC](https://discuss.elastic.co/t/logstash-best-practice/85425/7 "2017-05-15T07:06:24Z")

</div>

> Sure, but it's not clear to me how you'll utilize both servers (hence my question about load balancing). As opposed to Elasticsearch, Logstash instance don't form clusters.

--\> the load balancer is F5 with TCP

If I understand correctly F5 will do the balancing to the 2 clients servers and so I will have highly availability with the logstash also?  
Also read this form:

> [@How to make Logstash highly available](https://discuss.elastic.co/t/how-to-make-logstash-highly-available/29926/4):
>
> @vikas_gopal @magnusbaeck Check out this discussion as well:

and found that F5 is good for this configuration, Is it correct?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 15, 2017, 7:49am UTC](https://discuss.elastic.co/t/logstash-best-practice/85425/8 "2017-05-15T07:49:23Z")

</div>

> If I understand correctly F5 will do the balancing to the 2 clients servers and so I will have highly availability with the logstash also?

Yes.

---

<div class="post-metadata">

**Author:** ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)\
**Post date:** [May 15, 2017, 8:05am UTC](https://discuss.elastic.co/t/logstash-best-practice/85425/9 "2017-05-15T08:05:38Z")

</div>

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2017, 8:11am UTC](https://discuss.elastic.co/t/logstash-best-practice/85425/10 "2017-06-12T08:11:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
