# Sending data from 2 logstash nodes to an elasticsearch cluster

**URL:** <https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128>\
**Category:** Elasticsearch\
**Created:** [March 21, 2023, 5:37am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128 "2023-03-21T05:37:20Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [March 21, 2023, 5:37am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128/1 "2023-03-21T05:37:20Z")

</div>

Hi Folks,

I have 2 logstash nodes (version -8.6.2) that i want to send data to 2 elasticsearch nodes (version -8.6.2) ( a third node will be added soon to the cluster) . Do i just mention the elasticsearch nodes' in the ES output section like below , would that be enough?

```auto
 hosts => ["https://10.27.101.63:9200","https://10.27.101.247:9200"]

```

Would the data be sent to both ? or since its a cluster i'd just need to send to the master and would that take care of sharding and placing data on both nodes ?

master is 10.27.101.63

currently i have both elasticsearch nodes set in [master ,data] roles

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 21, 2023, 6:20am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128/2 "2023-03-21T06:20:39Z")

</div>

> [@Shreesh\_Narayanan](#):
>
> Would the data be sent to both ? or since its a cluster i'd just need to send to the master and would that take care of sharding and placing data on both nodes ?

The configuration you showed will send the data to one of the nodes in the cluster, which is the correct behaviour. When you send a bulk request to one of the nodes in the cluster it will write the data across the cluster, so you should not try to send data twice. The master node role is not involved in indexing (unless mappings or other things affecting the cluster state changes) so data should be sent to any of the data nodes.

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [March 21, 2023, 6:23am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128/3 "2023-03-21T06:23:24Z")

</div>

And is it load balanced automatically ? so as of now the data seems to be going the master /data node - 10.27.101.63 or would it always goto this one node all the time ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 21, 2023, 6:25am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128/4 "2023-03-21T06:25:13Z")

</div>

> [@Shreesh\_Narayanan](#):
>
> would it always goto this one node all the time ?

No. It can go to either node.

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [March 21, 2023, 6:29am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128/5 "2023-03-21T06:29:34Z")

</div>

Thank you for the swift response 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2023, 6:29am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128/6 "2023-04-18T06:29:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
