# Logstash Monitoring - Core Operations

**URL:** <https://discuss.elastic.co/t/logstash-monitoring-core-operations/100329>\
**Category:** Elastic Training\
**Created:** [September 13, 2017, 10:08am UTC](https://discuss.elastic.co/t/logstash-monitoring-core-operations/100329 "2017-09-13T10:08:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![SKumarMN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skumarmn/32/27537_2.png) [@SKumarMN](https://discuss.elastic.co/u/SKumarMN)\
**Post date:** [September 13, 2017, 10:08am UTC](https://discuss.elastic.co/t/logstash-monitoring-core-operations/100329/1 "2017-09-13T10:08:56Z")

</div>

I have a question related to slide 452 in core operations . It mentions as below

> configure your Logstash nodes to send metrics to your  
> production cluster ( **not your Monitoring cluster** ):  
> 452  
> xpack.monitoring.elasticsearch.url: "[http://PRODUCTION:9200](http://PRODUCTION:9200)"  
> xpack.monitoring.elasticsearch.username: "logstash\_system"  
> xpack.monitoring.elasticsearch.password: "changeme"

As a best practice for monitoring ES prod machines, it is recommended to have a dedicated monitoring cluster so that metrics from different cluster can be shipped from prod machines and stored in a separate machine for various advantages. but however for logstash monitoring , it is mentioned to send the logstash metrics to ES prod machine than the monitoring cluster. Its confusing. Can you please explain the reasoning

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [September 13, 2017, 12:03pm UTC](https://discuss.elastic.co/t/logstash-monitoring-core-operations/100329/2 "2017-09-13T12:03:23Z")

</div>

Yes, this can be a bit confusing. By sending the logs to the Production cluster, that Production cluster will actually forward the data to the monitoring cluster. This will result in the Logstash monitoring data showing up as part of your Production cluster in Kibana.

If you would not do that, that Logstash data would show up in Kibana under a separate "monitoring" cluster.

The docs have a bit more info: [https://www.elastic.co/guide/en/x-pack/current/monitoring-logstash.html](https://www.elastic.co/guide/en/x-pack/current/monitoring-logstash.html) (step 2).

---

<div class="post-metadata">

**Author:** ![SKumarMN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skumarmn/32/27537_2.png) [@SKumarMN](https://discuss.elastic.co/u/SKumarMN)\
**Post date:** [September 13, 2017, 4:35pm UTC](https://discuss.elastic.co/t/logstash-monitoring-core-operations/100329/3 "2017-09-13T16:35:52Z")

</div>

> [@abdon](#):
>
> Yes, this can be a bit confusing. By sending the logs to the Production cluster, that Production cluster will actually forward the data to the monitoring cluster. This will result in the Logstash monitoring data showing up as part of your Production cluster in Kibana.

Thanks for the explanation

The intention of having a dedicated server is not to load the production data with metrics or not to disturb it. So if we store this(logstash) metrics in prod server and x pack monitoring agents ships them to dedicated server wont it data duplication too in both prod and monitoring servers?

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [September 13, 2017, 4:58pm UTC](https://discuss.elastic.co/t/logstash-monitoring-core-operations/100329/4 "2017-09-13T16:58:16Z")

</div>

The intention of having is a dedicated monitoring cluster is to make sure the monitoring data available when the Production cluster goes down. The Production cluster being down would otherwise cause you not to be able to access the monitoring data, if you would store all of it in the same cluster.

The Logstash monitoring data will actually not be stored in the Production cluster. The Production cluster will forward it to the monitoring cluster, where the data will be stored. There is no data duplication.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2017, 4:58pm UTC](https://discuss.elastic.co/t/logstash-monitoring-core-operations/100329/5 "2017-10-13T16:58:26Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
