# Scaling out logstash

**URL:** <https://discuss.elastic.co/t/scaling-out-logstash/56188>\
**Category:** Logstash\
**Created:** [July 22, 2016, 2:28pm UTC](https://discuss.elastic.co/t/scaling-out-logstash/56188 "2016-07-22T14:28:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![DK\_3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dk_3/32/48003_2.png) [@DK\_3](https://discuss.elastic.co/u/DK_3)\
**Post date:** [July 22, 2016, 2:28pm UTC](https://discuss.elastic.co/t/scaling-out-logstash/56188/1 "2016-07-22T14:28:01Z")

</div>

Looking for the easiest approach to scale ELK with Docker (host network mode)

Currently I have 2 servers and each runs a single elasticsearch, logstash and kibana container.

The elasticsearch containers on each server run in master mode and can find each other with unicast discovery:

```auto
    discovery.zen.minimum_master_nodes: 2
    discovery.zen.ping.unicast.hosts: server1, server2

```

Each logstash container is configured with it's local elasticsearch container running on same server.

```auto
    output {
        elasticsearch {
            hosts => ["${HOST_IP}:9200"]
        }
    }

```

The Kibana container will also only talk to local elasticsearch but I'm assuming via discovery it'll find all others.  
A user can jump onto Kibana on any server to search all logs etc...

```auto
ELASTICSEARCH_URL=http://${HOST_IP}:9200

```

As I add more servers they'll run using the same setup. 1 master elasticsearch container and 1 logstash container and 1 Kibana

Does this setup make sense?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 22, 2016, 4:09pm UTC](https://discuss.elastic.co/t/scaling-out-logstash/56188/2 "2016-07-22T16:09:57Z")

</div>

It's certainly not crazy, but

- ES, Logstash, and Kibana all have different performance characteristics and different ways and needs of scaling, and
- ES and Logstash will compete for resources.

Having your configuration assume that all three services run on the same machine could paint you into a corner if you ever decide you want to break things up. It probably won't be that hard to untangle but I'd prefer not making such assumptions in the first place.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:46am UTC](https://discuss.elastic.co/t/scaling-out-logstash/56188/3 "2017-07-06T04:46:50Z")

</div>


