# Recommendation for Elastic Search sizing for 45,000 Events per second

**URL:** <https://discuss.elastic.co/t/recommendation-for-elastic-search-sizing-for-45-000-events-per-second/179181>\
**Category:** Elasticsearch\
**Created:** [May 1, 2019, 7:59am UTC](https://discuss.elastic.co/t/recommendation-for-elastic-search-sizing-for-45-000-events-per-second/179181 "2019-05-01T07:59:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![oany\_81](https://avatars.discourse-cdn.com/v4/letter/o/7feea3/32.png) [@oany\_81](https://discuss.elastic.co/u/oany_81)\
**Post date:** [May 1, 2019, 7:59am UTC](https://discuss.elastic.co/t/recommendation-for-elastic-search-sizing-for-45-000-events-per-second/179181/1 "2019-05-01T07:59:04Z")

</div>

Hi techies,

- What would be recommended infrastructure for Elastic Search for a workload of 45,000 events per second?
- What would be the recommended compute requirements?
- How many clusters I should have with bare minimum Master and Data Nodes?
- Size of payload is approx 0.5 kb to 1 KB.

Your quick assistance would be appreciated.

---

<div class="post-metadata">

**Author:** ![oany\_81](https://avatars.discourse-cdn.com/v4/letter/o/7feea3/32.png) [@oany\_81](https://discuss.elastic.co/u/oany_81)\
**Post date:** [May 5, 2019, 5:53pm UTC](https://discuss.elastic.co/t/recommendation-for-elastic-search-sizing-for-45-000-events-per-second/179181/2 "2019-05-05T17:53:06Z")

</div>

Hi community,  
Still waiting for your recommendation on my query.

Regards,  
Oan Ali

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 5, 2019, 8:00pm UTC](https://discuss.elastic.co/t/recommendation-for-elastic-search-sizing-for-45-000-events-per-second/179181/3 "2019-05-05T20:00:54Z")

</div>

Is the 45,000 a peak or average rate? How long are you going to keep the data once it is indexed? What type of data is it? What do the query patterns and latency requirements look like? What type of hardware are you looking to deploy on?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [May 5, 2019, 11:57pm UTC](https://discuss.elastic.co/t/recommendation-for-elastic-search-sizing-for-45-000-events-per-second/179181/4 "2019-05-05T23:57:18Z")

</div>

Just FYI, we have just turned winlogbeat on many domain controllers, it has ignore\_old: 72h, so we had an instant backlog of data. We started ingesting at about 10K events/sec to 6 Dell R640's running logstash and they are elastic data nodes on spinning disk. (Budget won over performance). Logstash had 3 ingest pipelines. I changed that to 8 and ingest went up to over 20K, increasing to 12 got to almost 50K/sec. Logstash pipelines will use a CPU per thread when busy. This was on top of all other normal ingest approx 3K/sec. We sustained this rate for a few hours until the 72 hours of old data was ingested.

Our design is for eventual 10K/sec, so I think we'll be able to do that.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [May 6, 2019, 9:20am UTC](https://discuss.elastic.co/t/recommendation-for-elastic-search-sizing-for-45-000-events-per-second/179181/5 "2019-05-06T09:20:18Z")

</div>

> [@rugenl](#):
>
> Budget won over performance

Maybe, but maybe you could achieve your target performance with fewer nodes if you were using SSDs. The [nightly benchmarks](https://elasticsearch-benchmarks.elastic.co/index.html#tracks/http-logs/nightly/oss/30d) run on a 3-node cluster (with SSDs) and exceed the performance you're seeing here by quite some margin.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 6, 2019, 9:29am UTC](https://discuss.elastic.co/t/recommendation-for-elastic-search-sizing-for-45-000-events-per-second/179181/6 "2019-05-06T09:29:56Z")

</div>

The size of the cluster also heavily depend on how long you are keeping the data and what your query requirements are, which you have not yet detailed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2019, 9:30am UTC](https://discuss.elastic.co/t/recommendation-for-elastic-search-sizing-for-45-000-events-per-second/179181/7 "2019-06-03T09:30:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
