# Production configuration question

**URL:** <https://discuss.elastic.co/t/production-configuration-question/350302>\
**Category:** Elasticsearch\
**Created:** [January 3, 2024, 12:04pm UTC](https://discuss.elastic.co/t/production-configuration-question/350302 "2024-01-03T12:04:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aleksandar\_Aleksand1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aleksandar_aleksand1/32/123368_2.png) [@Aleksandar\_Aleksand1](https://discuss.elastic.co/u/Aleksandar_Aleksand1)\
**Post date:** [January 3, 2024, 12:04pm UTC](https://discuss.elastic.co/t/production-configuration-question/350302/1 "2024-01-03T12:04:17Z")

</div>

Hi all,

I am preparing the following elasticsearch cluster architecture:  
Total 6 Nodes:

- 1 Node with roles: master and remote\_cluster\_client
- 3 Nodes with roles: data, data\_hot, data\_content and ingest
- 1 Node with role data\_warm
- 1 Node with Kibana

Ideally the goal is to store logs from the custom applications, developed by me. The logs will be something like 15k -20k per day. The logs will stay on the hot nodes for 2 months, because they will be accessed from Kibana for reporting. After this 2 months the logs will go to the warm Node (using ILM). After 6 months staying on the warm Node, the index will be sent to S3 archive.

The questions that I have are the following:

- Is the architecture suitable for the required job?
- Is 1 Node with Master role enough? What will happen if the master goes down?
- According to the documentation, what I understood is that you can configure the ILM policy of the warm node to keep the data for XXX period and before deleting it to archive it to S3. What is the procedure to restore logs for a specific date that has already been sent to S3 (not in the warm Node period)?

Thank you

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 3, 2024, 12:41pm UTC](https://discuss.elastic.co/t/production-configuration-question/350302/2 "2024-01-03T12:41:06Z")

</div>

> [@Aleksandar\_Aleksand1](#):
>
> - 1 Node with roles: master and remote\_cluster\_client
> - 3 Nodes with roles: data, data\_hot, data\_content and ingest
> - 1 Node with role data\_warm

You should always look to have 3 master eligible nodes as that will allow the cluster to continue operating if 1 is unavailable. It would therefore be better to have 3 nodes with master, data\_hot, data\_content and ingest roles. Unless you are going to have multiple clusters and use cross-cluster serach I am not sure why you would use remote\_cluster\_client. If you want warm data to also be highly available I would have 2 data nodes with the data\_warm role.

> [@Aleksandar\_Aleksand1](#):
>
> Is 1 Node with Master role enough? What will happen if the master goes down?

No. That would make the cluster unavaiable and you would lose all data if the master node was permanently lost.

---

<div class="post-metadata">

**Author:** ![Aleksandar\_Aleksand1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aleksandar_aleksand1/32/123368_2.png) [@Aleksandar\_Aleksand1](https://discuss.elastic.co/u/Aleksandar_Aleksand1)\
**Post date:** [January 3, 2024, 12:54pm UTC](https://discuss.elastic.co/t/production-configuration-question/350302/3 "2024-01-03T12:54:43Z")

</div>

Thank you very much, Christian.  
I will put master role also on the data nodes. In this case, is it possible to set a priority that the master role will be hold only by the master node and only if failure happens to be transferred to the other nodes?  
What kind of backup strategy (apart from the snapshots) is good to be implemented on the nodes on server level?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 3, 2024, 1:07pm UTC](https://discuss.elastic.co/t/production-configuration-question/350302/4 "2024-01-03T13:07:42Z")

</div>

> [@Aleksandar\_Aleksand1](#):
>
> I will put master role also on the data nodes. In this case, is it possible to set a priority that the master role will be hold only by the master node and only if failure happens to be transferred to the other nodes?

Make the 3 hot data nodes master eligible and do not use another dedicated master node. You want 3 master eligieble nodes, not 4. You can not (and do not need to) control which node is elected master at any point.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2024, 1:08pm UTC](https://discuss.elastic.co/t/production-configuration-question/350302/5 "2024-01-31T13:08:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
