# New Cluster Setup

**URL:** <https://discuss.elastic.co/t/new-cluster-setup/112264>\
**Category:** Elasticsearch\
**Created:** [December 18, 2017, 3:20pm UTC](https://discuss.elastic.co/t/new-cluster-setup/112264 "2017-12-18T15:20:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rudolphk](https://avatars.discourse-cdn.com/v4/letter/r/b9e5f3/32.png) [@rudolphk](https://discuss.elastic.co/u/rudolphk)\
**Post date:** [December 18, 2017, 3:20pm UTC](https://discuss.elastic.co/t/new-cluster-setup/112264/1 "2017-12-18T15:20:35Z")

</div>

We are in the process of moving one of our datasets from an on-premise cluster to a self-managed cluster on AWS. We are planning on setting up some dedicated master nodes (something we have not done in the past) and we are considering allocating some dedicated query nodes as well. My question is twofold 1) are dedicated query nodes worth it? 2) . Should I direct my indexing (i.e. Logstash) to the query nodes or set up a separate load balancer to access the data nodes?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 18, 2017, 3:37pm UTC](https://discuss.elastic.co/t/new-cluster-setup/112264/2 "2017-12-18T15:37:55Z")

</div>

It depends. Mostly on the load you'll have.  
A load balancer is not needed and I'd prefer using a coordinating node instead.

Did you also consider [cloud.elastic.co](http://cloud.elastic.co)? It runs on AWS (or GCP) and is fully managed by elastic. It has x-pack, automatic backups, ...

---

<div class="post-metadata">

**Author:** ![rudolphk](https://avatars.discourse-cdn.com/v4/letter/r/b9e5f3/32.png) [@rudolphk](https://discuss.elastic.co/u/rudolphk)\
**Post date:** [December 18, 2017, 4:15pm UTC](https://discuss.elastic.co/t/new-cluster-setup/112264/3 "2017-12-18T16:15:48Z")

</div>

We are currently indexing around 22K doc/sec. Since we are using Logstash to transform the data, it does not appear that setting up ingest nodes would help. It sounds like setting up one or more coordinating nodes would be our best option.

I have not performed an in-depth eval of Elastic Cloud, but it appears that this would be an expensive option for us. We are indexing (with 1 replica) around 2TB of data per day.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 18, 2017, 4:43pm UTC](https://discuss.elastic.co/t/new-cluster-setup/112264/4 "2017-12-18T16:43:25Z")

</div>

> It sounds like setting up one or more coordinating nodes would be our best option.

Probably a good choice. If you can afford it, start:

- 3 master only nodes
- x coordinating nodes
- y data nodes

Have a look at [https://speakerdeck.com/elastic/netsecureday-managing-your-black-friday-logs](https://speakerdeck.com/elastic/netsecureday-managing-your-black-friday-logs)

---

<div class="post-metadata">

**Author:** ![rudolphk](https://avatars.discourse-cdn.com/v4/letter/r/b9e5f3/32.png) [@rudolphk](https://discuss.elastic.co/u/rudolphk)\
**Post date:** [December 18, 2017, 4:45pm UTC](https://discuss.elastic.co/t/new-cluster-setup/112264/5 "2017-12-18T16:45:35Z")

</div>

Thanks David! I'll check out your presentation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2018, 4:45pm UTC](https://discuss.elastic.co/t/new-cluster-setup/112264/6 "2018-01-15T16:45:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
