# Sizing ELK cluster for 12GB daily logs

**URL:** <https://discuss.elastic.co/t/sizing-elk-cluster-for-12gb-daily-logs/158176>\
**Category:** Elasticsearch\
**Created:** [November 26, 2018, 12:22pm UTC](https://discuss.elastic.co/t/sizing-elk-cluster-for-12gb-daily-logs/158176 "2018-11-26T12:22:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gerasimos](https://avatars.discourse-cdn.com/v4/letter/g/d26b3c/32.png) [@gerasimos](https://discuss.elastic.co/u/gerasimos)\
**Post date:** [November 26, 2018, 12:22pm UTC](https://discuss.elastic.co/t/sizing-elk-cluster-for-12gb-daily-logs/158176/1 "2018-11-26T12:22:46Z")

</div>

Hello,

I am moving an ELK demo deployment (FileBeats -\> Logstash cluster -\> ElasticSearch cluster) to a production one. I am expecting ~12GB of daily logs to be fed into ElasticSearch, with a retention period of 1 year. I would like to ask about the sizing of the overall solution, and here is what I am thinking of:

1. 2 x Logstash nodes (8 GB, 8 vCores each)
2. 3 x ES Master nodes (6 GB, 4 vCores each)
3. 3 x ES Data nodes (32 GB, 12 vCores each)

Questions:

1. Are the above adequate as a starting point? Can I safely reduce them?
2. Do the specs of each node make sense for the expected amount of traffic? Are they over-sized?
3. Do I need 3 ES Master nodes?
4. Is a load-balancer required in front of ES nodes?

Thank you,  
Gerasimos

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 27, 2018, 7:11am UTC](https://discuss.elastic.co/t/sizing-elk-cluster-for-12gb-daily-logs/158176/2 "2018-11-27T07:11:31Z")

</div>

If we make the assumption that you logs will take up the same amount of space on disk as the raw form and that you will have one replica, that gives around 8.5TB of data on disk in total. You can likely reduce this by [optimizing your data](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/tune-for-disk-usage.html). That is almost 3TB per data node, which should be fine given your specification assuming you [follow best practices](https://www.elastic.co/webinars/optimizing-storage-efficiency-in-elasticsearch).

> [@gerasimos](#):
>
> Are the above adequate as a starting point? Can I safely reduce them?

I think this looks like a good starting point. Since you are indexing relatively little data per day you may be able to make your data nodes master-eligible and might not require the dedicated master nodes.

> [@gerasimos](#):
>
> Do the specs of each node make sense for the expected amount of traffic? Are they over-sized?

Memory-wise I think this looks good, but I suspect you could reduce the amount of allocated CPU if you wanted to. You can probably half it across the board.

> [@gerasimos](#):
>
> Do I need 3 ES Master nodes?

Not necessarily. Dedicated master nodes are typically added for larger clusters or if the cluster is under heavy load and therefore suffering from instability.

> [@gerasimos](#):
>
> Is a load-balancer required in front of ES nodes?

No, that is generally not required.

If you are going to use Kibana, you may want a host for that as well. It is often deployed together with a coordinating-only node which acts as a load-balancer.

---

<div class="post-metadata">

**Author:** ![gerasimos](https://avatars.discourse-cdn.com/v4/letter/g/d26b3c/32.png) [@gerasimos](https://discuss.elastic.co/u/gerasimos)\
**Post date:** [November 27, 2018, 7:46pm UTC](https://discuss.elastic.co/t/sizing-elk-cluster-for-12gb-daily-logs/158176/3 "2018-11-27T19:46:40Z")

</div>

Thank you Christian!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2018, 7:47pm UTC](https://discuss.elastic.co/t/sizing-elk-cluster-for-12gb-daily-logs/158176/4 "2018-12-25T19:47:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
