# Multitier Storage with ES

**URL:** <https://discuss.elastic.co/t/multitier-storage-with-es/54029>\
**Category:** Elasticsearch\
**Created:** [June 27, 2016, 11:19am UTC](https://discuss.elastic.co/t/multitier-storage-with-es/54029 "2016-06-27T11:19:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexander\_Trumper](https://avatars.discourse-cdn.com/v4/letter/a/3e96dc/32.png) [@Alexander\_Trumper](https://discuss.elastic.co/u/Alexander_Trumper)\
**Post date:** [June 27, 2016, 11:19am UTC](https://discuss.elastic.co/t/multitier-storage-with-es/54029/1 "2016-06-27T11:19:34Z")

</div>

I'm currently evalutating ELK for logfile storage and analysis.  
Since we may acquire up to 50GB per day we need to use different storage pathes  
according to the age of indices.

So the idea I'd like to ask for feedback is this:

I have two nodes which will run three instances of elasticsearch , each.  
On every node there will be a fast, a medium and a slow storage tier mounted in filesystem  
and the elasticsearch instance will be started with the according storagepath,  
where fast is flash based for recent indices, medium is SAS-HDD and slow is SATA-HDD for archive.

```
## Node 1, 3 Instanzen
bin/elasticsearch --node.vm vm1 --node.perf fast -Des.path.data=/mnt/fast
bin/elasticsearch --node.vm vm1 --node.perf medium -Des.path.data=/mnt/medium
bin/elasticsearch --node.vm vm1 --node.perf slow -Des.path.data=/mnt/slow

## Node 2, 3 Instanzen
bin/elasticsearch --node.vm vm2 --node.perf fast -Des.path.data=/mnt/fast
bin/elasticsearch --node.vm vm2 --node.perf medium -Des.path.data=/mnt/medium
bin/elasticsearch --node.vm vm2 --node.perf slow -Des.path.data=/mnt/slow

### VM-awareness
cluster.routing.allocation.awareness.attributes: vm

```

Using either an external script or curator I'd want to tune the settings for an index  
older than n days:

```
### Fast Indices
PUT test/_settings
{
  "index.routing.allocation.exclude.perf": "slow, medium"
}

### medium Indices
PUT test/_settings
{
  "index.routing.allocation.exclude.perf": "slow, fast"
}

### slow Indices
PUT test/_settings
{
  "index.routing.allocation.exclude.perf": "fast, medium"
}

```

If I get it right, ES would migrate the indices to the according instance which uses  
the configured storage tier.

Is this a totally wrong idea or could you give any recommendations on this?

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/c707d2c6ca9cfabd1559c469dcb1a02640bb4d5a.png)

---

<div class="post-metadata">

**Author:** ![abeyad](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@abeyad](https://discuss.elastic.co/u/abeyad)\
**Post date:** [June 27, 2016, 6:22pm UTC](https://discuss.elastic.co/t/multitier-storage-with-es/54029/2 "2016-06-27T18:22:45Z")

</div>

We wouldn't recommend running more than one instance of ES on the same machine. Your desired setup sounds very much like the hot/warm architecture we would advocate, see this blog post for details: [https://www.elastic.co/blog/hot-warm-architecture](https://www.elastic.co/blog/hot-warm-architecture)

---

<div class="post-metadata">

**Author:** ![Alexander\_Trumper](https://avatars.discourse-cdn.com/v4/letter/a/3e96dc/32.png) [@Alexander\_Trumper](https://discuss.elastic.co/u/Alexander_Trumper)\
**Post date:** [June 28, 2016, 6:03am UTC](https://discuss.elastic.co/t/multitier-storage-with-es/54029/3 "2016-06-28T06:03:44Z")

</div>

@abeyad Thank you very much for your feedback and the link 🙂 I think I will follow the blog more closely from now on 😉  
I will try the hot/warm architecture with dedicated nodes on my playground.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 28, 2016, 11:39am UTC](https://discuss.elastic.co/t/multitier-storage-with-es/54029/4 "2016-06-28T11:39:15Z")

</div>

> [@abeyad](#):
>
> We wouldn't recommend running more than one instance of ES on the same machine.

One caveat, you can if you have the resources; CPU and RAM primarily.

---

<div class="post-metadata">

**Author:** ![Alexander\_Trumper](https://avatars.discourse-cdn.com/v4/letter/a/3e96dc/32.png) [@Alexander\_Trumper](https://discuss.elastic.co/u/Alexander_Trumper)\
**Post date:** [June 29, 2016, 11:24am UTC](https://discuss.elastic.co/t/multitier-storage-with-es/54029/5 "2016-06-29T11:24:12Z")

</div>

> [@warkolm](#):
>
> if you have the resources; CPU and RAM primarily.

after thinking it through more machines make more sense. We could have more pathes to the storage available if we can manange to have the VMs running in different blade centers, so we won't eat all the I/O bandwith and IOPS in a single enclosure with a hand full of VMs 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:39pm UTC](https://discuss.elastic.co/t/multitier-storage-with-es/54029/6 "2017-07-05T22:39:36Z")

</div>


