I would like to implement the elk stack for log management for a SIEM.
In a production context I would like to create a cluster of 3 elastic nodes.
What are your advices and best practices?
2 x node.roles: [ master, voting_only, ... ]
1 x node.roles: [ master, voting_only, data ... ]
How many nodes for logstash?
And for kibana?
And what are the hardware recommendations for each node in a virtualized environment?
Number of cores? RAM? How many disks? What size?
Someone who has worked on a virtualized architecture with a cluster of 3 elastic nodes, 2 logstash and 1 kibana can share his hardware configuration.
CPU ? RAM ? number of disks and their sizes ?
I know that the infrastructure can be evolving but I would like to have an idea.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.