# Requirements production cluster

**URL:** <https://discuss.elastic.co/t/requirements-production-cluster/306029>\
**Category:** Elasticsearch\
**Created:** [May 31, 2022, 11:11am UTC](https://discuss.elastic.co/t/requirements-production-cluster/306029 "2022-05-31T11:11:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![diegz](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@diegz](https://discuss.elastic.co/u/diegz)\
**Post date:** [May 31, 2022, 11:11am UTC](https://discuss.elastic.co/t/requirements-production-cluster/306029/1 "2022-05-31T11:11:26Z")

</div>

Hello everyone,

I would like to implement the elk stack for log management for a SIEM.  
In a production context I would like to create a cluster of 3 elastic nodes.  
What are your advices and best practices?  
2 x node.roles: [master, voting\_only, ...]  
1 x node.roles: [master, voting\_only, data ...]

How many nodes for logstash?  
And for kibana?

And what are the hardware recommendations for each node in a virtualized environment?  
Number of cores? RAM? How many disks? What size?

Thank you very much in advance for your advice

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [May 31, 2022, 1:09pm UTC](https://discuss.elastic.co/t/requirements-production-cluster/306029/2 "2022-05-31T13:09:57Z")

</div>

Hi!!  
Maybe this [discussion](https://discuss.elastic.co/t/elasticsearch-large-cluster-configuration-requirments/305512) can help you.

---

<div class="post-metadata">

**Author:** ![diegz](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@diegz](https://discuss.elastic.co/u/diegz)\
**Post date:** [June 1, 2022, 7:18am UTC](https://discuss.elastic.co/t/requirements-production-cluster/306029/3 "2022-06-01T07:18:55Z")

</div>

Hi,

Thank you @RabBit_BR.

Someone who has worked on a virtualized architecture with a cluster of 3 elastic nodes, 2 logstash and 1 kibana can share his hardware configuration.  
CPU ? RAM ? number of disks and their sizes ?

I know that the infrastructure can be evolving but I would like to have an idea.

Best regards,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2022, 7:19am UTC](https://discuss.elastic.co/t/requirements-production-cluster/306029/4 "2022-06-29T07:19:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
