# Regular ELK stack on AWS

**URL:** <https://discuss.elastic.co/t/regular-elk-stack-on-aws/169997>\
**Category:** Elasticsearch\
**Created:** [February 26, 2019, 11:50am UTC](https://discuss.elastic.co/t/regular-elk-stack-on-aws/169997 "2019-02-26T11:50:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahulkumar1](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@rahulkumar1](https://discuss.elastic.co/u/rahulkumar1)\
**Post date:** [February 26, 2019, 11:50am UTC](https://discuss.elastic.co/t/regular-elk-stack-on-aws/169997/1 "2019-02-26T11:50:09Z")

</div>

I am using a traditional ELK stack on AWS with the below Architecture:

AZ1: 1x Logstash (ALB+ASG) AZ2: 1x Logstash  
AZ1: 3x Master Nodes AZ2: 2x Master Nodes  
AZ1: 2x Data Nodes AZ2: 2x Data Nodes  
AZ1: 1x Kibana (ALB+ASG) AZ2: 1x Kibana

ALB: Application Load Balancer  
ASG: Autoscaling Groups

Is the above combination recommended ? Should I be using a ALB or a network load balancer ?

To send logs to Logstash should I use RSyslog(for linux) and or Beats( for Windows) ? or is this really not a mandatory requirement ? If not how will the logs be sent to Logstash ?

What is a coordinating node ? in the above combination is a coordinating node required ?

---

<div class="post-metadata">

**Author:** ![rahulkumar1](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@rahulkumar1](https://discuss.elastic.co/u/rahulkumar1)\
**Post date:** [March 6, 2019, 5:09pm UTC](https://discuss.elastic.co/t/regular-elk-stack-on-aws/169997/2 "2019-03-06T17:09:51Z")

</div>

Could anyone share some ELK architectures on ELK ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2019, 5:09pm UTC](https://discuss.elastic.co/t/regular-elk-stack-on-aws/169997/3 "2019-04-03T17:09:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
