Requirements production cluster

Hello everyone,

I would like to implement the elk stack for log management for a SIEM.
In a production context I would like to create a cluster of 3 elastic nodes.
What are your advices and best practices?
2 x node.roles: [ master, voting_only, ... ]
1 x node.roles: [ master, voting_only, data ... ]

How many nodes for logstash?
And for kibana?

And what are the hardware recommendations for each node in a virtualized environment?
Number of cores? RAM? How many disks? What size?

Thank you very much in advance for your advice

Maybe this discussion can help you.


Thank you @RabBit_BR.

Someone who has worked on a virtualized architecture with a cluster of 3 elastic nodes, 2 logstash and 1 kibana can share his hardware configuration.
CPU ? RAM ? number of disks and their sizes ?

I know that the infrastructure can be evolving but I would like to have an idea.

Best regards,

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.