# Query multiple ES nodes from single Kibana instance

**URL:** <https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071>\
**Category:** Elasticsearch\
**Created:** [February 17, 2016, 9:23pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071 "2016-02-17T21:23:53Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![sck](https://avatars.discourse-cdn.com/v4/letter/s/ccd318/32.png) [@sck](https://discuss.elastic.co/u/sck)\
**Post date:** [February 17, 2016, 9:23pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/1 "2016-02-17T21:23:53Z")

</div>

First, apologies if the category is incorrect, I think this question is half ES and half Kibana.

Scenario:

I have 10+ machines (on the same subnet) each running their own elasticsearch instance (plus logstash & logstash-forwarder). On each of these 10+ servers I'm using logstash to ingest HTTP proxy logs (local, on each of the 10+ machines). On another subnet I have a single ELK server that is receiving logs from those 10+ machines (mentioned above) via logstash-forwarder. The logs i'm sending via logstash-forwarder are _not_ the HTTP proxy logs. I don't want to send the proxy logs via logstash-forwarder due to bandwidth (proxy logs can easily reach 4GB+ in a single day).

Goal:

From my single ELK server I would like to be able to query the elasticsearch instances on the 10+ machines using Kibana. Even though the ELK server is on a different subnet I can still reach the 10+ machines running elasticsearch/logstash/logstash-forwarder. My HTTP proxy logs contain user-agent, URL, IP etc.. all in json format, I would like to be able to run a search from the ELK server (Kibana) that would run on 10+ machines to look for say a specific "user-agent"

TL;DR -- I want to search for data across 10+ independent elasticsearch instances/nodes from a single Kibana interface. What is the best way to accomplish this?

Hopefully this makes sense!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 17, 2016, 9:24pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/2 "2016-02-17T21:24:55Z")

</div>

You could use a Tribe node to do this - [https://www.elastic.co/guide/en/elasticsearch/reference/2.2/modules-tribe.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.2/modules-tribe.html)

---

<div class="post-metadata">

**Author:** ![sck](https://avatars.discourse-cdn.com/v4/letter/s/ccd318/32.png) [@sck](https://discuss.elastic.co/u/sck)\
**Post date:** [February 17, 2016, 10:24pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/3 "2016-02-17T22:24:54Z")

</div>

Thanks, Mark!

Would Tribe be required in my scenario since I don't have different clusters? Could the ELK server and the 10+ machines be part of the same cluster? If so, any pointers on how to make that work?

_edit_ Also, is there any documentation on how to configure/create a "tribe node"?

Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 18, 2016, 2:33am UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/4 "2016-02-18T02:33:50Z")

</div>

So your 10 servers are in a single cluster?

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [February 18, 2016, 7:42am UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/5 "2016-02-18T07:42:23Z")

</div>

From what I read, the single ELK server in another subnet he mentioned is only for storing Kibana index, and he wants that Kibana to be able to query data from 10+ ES nodes (10+ single node ES cluster 😃).

@sck: 4GB+ a day a not large in traffic, I'm not sure why you don't want to store all logs into one single ES cluster. On our prod environment, we sending about 200GB per day of logs from multiple servers into one ES cluster.

---

<div class="post-metadata">

**Author:** ![sck](https://avatars.discourse-cdn.com/v4/letter/s/ccd318/32.png) [@sck](https://discuss.elastic.co/u/sck)\
**Post date:** [February 18, 2016, 2:57pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/6 "2016-02-18T14:57:05Z")

</div>

While the 10+ servers are on the same subnet they are geographically dispersed. So yes, 4GB is typically not a lot of traffic, but in this scenario it is not feasible. Sounds like the tribe node is the best way to go. Now i'm trying to find some info on how to setup a tribe node. Would the tribe node be setup on my ELK server?

Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 18, 2016, 7:14pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/7 "2016-02-18T19:14:41Z")

</div>

Check that link I posted, it explains how to setup a tribe node.

---

<div class="post-metadata">

**Author:** ![sck](https://avatars.discourse-cdn.com/v4/letter/s/ccd318/32.png) [@sck](https://discuss.elastic.co/u/sck)\
**Post date:** [February 18, 2016, 8:34pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/8 "2016-02-18T20:34:18Z")

</div>

Thanks! Would the tribe node config go into the elasticsearch.yml? Kind of confused as to where it should go.

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 18, 2016, 8:45pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/9 "2016-02-18T20:45:47Z")

</div>

Yes, that is correct.

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [February 19, 2016, 1:36am UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/10 "2016-02-19T01:36:05Z")

</div>

Given that you can use tribe nodes, will the search latency acceptable when one ES node has to go to 10+ ES instances separated geographically to get data?

Do you need to search data from 10+ nodes in real time? If not I still prefer using something to slowly ship data from 10+ nodes to a central ES node where we can do whatever we want at high speed. It would be easier than having to maintain separate ES nodes.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 19, 2016, 11:11pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/11 "2016-02-19T23:11:36Z")

</div>

Define acceptable 🙂  
This is really something that you would need to test.

---

<div class="post-metadata">

**Author:** ![thn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thn/32/8061_2.png) [@thn](https://discuss.elastic.co/u/thn)\
**Post date:** [February 25, 2016, 2:03pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/12 "2016-02-25T14:03:14Z")

</div>

Tribe Node is good when you want to do federated search across indices in multiple clusters.

If you have multiple indices in one cluster, you can simply use the Client Node. Point Kibana to this Client Node and it should work.

If you have to use the Tribe Node, you need to "initiate a .kibana" index manually or something similar so Kibana knows where to put its data. Under the hood, Kibana stores its data in an index in ES (if you do not know that) With the Tribe Node setup, Kibana will be confused about where to put its own index, that's why you'll need to do it "manually"

---

<div class="post-metadata">

**Author:** ![sck](https://avatars.discourse-cdn.com/v4/letter/s/ccd318/32.png) [@sck](https://discuss.elastic.co/u/sck)\
**Post date:** [February 25, 2016, 3:09pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/13 "2016-02-25T15:09:37Z")

</div>

Thanks All, this has been really helpful!

To initiate the kibana index manually, could/would that be done using curl?

Thanks!

---

<div class="post-metadata">

**Author:** ![thn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thn/32/8061_2.png) [@thn](https://discuss.elastic.co/u/thn)\
**Post date:** [February 25, 2016, 3:43pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/14 "2016-02-25T15:43:48Z")

</div>

Yes, that should work. You can find more info from the link below

[http://rogerwelin.github.io/kibana/elasticsearch/2015/03/06/kibana4-on-elasticsearch-tribe-node.html](http://rogerwelin.github.io/kibana/elasticsearch/2015/03/06/kibana4-on-elasticsearch-tribe-node.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:13pm UTC](https://discuss.elastic.co/t/query-multiple-es-nodes-from-single-kibana-instance/42071/15 "2017-07-05T23:13:42Z")

</div>


