# Strange issue with 2 seperate ELK servers

**URL:** <https://discuss.elastic.co/t/strange-issue-with-2-seperate-elk-servers/19814>\
**Category:** Elasticsearch\
**Created:** [September 16, 2014, 1:51pm UTC](https://discuss.elastic.co/t/strange-issue-with-2-seperate-elk-servers/19814 "2014-09-16T13:51:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kevin\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_m/32/69498_2.png) [@Kevin\_M](https://discuss.elastic.co/u/Kevin_M)\
**Post date:** [September 16, 2014, 1:51pm UTC](https://discuss.elastic.co/t/strange-issue-with-2-seperate-elk-servers/19814/1 "2014-09-16T13:51:31Z")

</div>

So I have 1 ELK server setup and working just fine IP is 172.16.40.28. We  
wanted to build a second one to log different servers and for several  
reasons keep the data seperate. So I built the new server and setup ELK  
again, all seems fine. The IP of the new server is 172.16.40.29. When I go  
to the new server IP kibana page I see all the data from the first ELK  
server. I have verified that my PC (through netstat) is connecting to .29  
and that on .29 through netstat shows me connecting. I tried clearing  
cookies and cache - any thoughts or help? when new data comes in I see it  
on both servers Kibana pages - so it's almost like Kibana is pointing to  
another ES server but I verified it is not in the config.js

Maybe I don't need to build another server but I am new to ELK and scaling  
it out in a cluster is over my head at this point

--  
Thanks,  
Kevin

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/10e468db-e862-4646-b52f-ac7f9b6a7c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/10e468db-e862-4646-b52f-ac7f9b6a7c35%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 16, 2014, 7:59pm UTC](https://discuss.elastic.co/t/strange-issue-with-2-seperate-elk-servers/19814/2 "2014-09-16T19:59:40Z")

</div>

By default ES uses a discovery method that allows any node with the same  
cluster name to join an existing node with the same cluster name, thereby  
forming one cluster.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

and you want to look at unicast discovery if you want to know more.

The quick solution here is to stop the new ELK server, change the  
cluster.name (  
[Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/setup-configuration.html#cluster-name))  
and then restart the node.

You may find you need to delete some data though, if you're new then  
install plugins like ElasticHQ and kopf, they will give you some good  
visual insight into Elasticsearch and lets you manage it via the GUI.

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 16 September 2014 23:51, Kevin M [mcgkev29@gmail.com](mailto:mcgkev29@gmail.com) wrote:

> So I have 1 ELK server setup and working just fine IP is 172.16.40.28. We  
> wanted to build a second one to log different servers and for several  
> reasons keep the data seperate. So I built the new server and setup ELK  
> again, all seems fine. The IP of the new server is 172.16.40.29. When I go  
> to the new server IP kibana page I see all the data from the first ELK  
> server. I have verified that my PC (through netstat) is connecting to .29  
> and that on .29 through netstat shows me connecting. I tried clearing  
> cookies and cache - any thoughts or help? when new data comes in I see it  
> on both servers Kibana pages - so it's almost like Kibana is pointing to  
> another ES server but I verified it is not in the config.js
> 
> Maybe I don't need to build another server but I am new to ELK and scaling  
> it out in a cluster is over my head at this point
> 
> --  
> Thanks,  
> Kevin
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/10e468db-e862-4646-b52f-ac7f9b6a7c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/10e468db-e862-4646-b52f-ac7f9b6a7c35%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/10e468db-e862-4646-b52f-ac7f9b6a7c35%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/10e468db-e862-4646-b52f-ac7f9b6a7c35%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624ac-y2j7pAbMiidnFvwnqma\_jS94dzLk\_DihCjsPPmYoQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624ac-y2j7pAbMiidnFvwnqma_jS94dzLk_DihCjsPPmYoQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Kevin\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_m/32/69498_2.png) [@Kevin\_M](https://discuss.elastic.co/u/Kevin_M)\
**Post date:** [September 17, 2014, 12:49pm UTC](https://discuss.elastic.co/t/strange-issue-with-2-seperate-elk-servers/19814/3 "2014-09-17T12:49:05Z")

</div>

Thanks you for the detailed information - changed the cluster name worked  
well. The plugins were also easy to install - thanks again!

On Tuesday, September 16, 2014 4:00:20 PM UTC-4, Mark Walkom wrote:

> By default ES uses a discovery method that allows any node with the same  
> cluster name to join an existing node with the same cluster name, thereby  
> forming one cluster.  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/modules-discovery-zen.html)  
> and you want to look at unicast discovery if you want to know more.
> 
> The quick solution here is to stop the new ELK server, change the  
> cluster.name (  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/setup-configuration.html#cluster-name))  
> and then restart the node.
> 
> You may find you need to delete some data though, if you're new then  
> install plugins like ElasticHQ and kopf, they will give you some good  
> visual insight into Elasticsearch and lets you manage it via the GUI.
> 
> Regards,  
> Mark Walkom
> 
> Infrastructure Engineer  
> Campaign Monitor  
> email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com) \<javascript:\>  
> web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> 
> On 16 September 2014 23:51, Kevin M \<[mcgk...@gmail.com](mailto:mcgk...@gmail.com) \<javascript:\>\>  
> wrote:
> 
> > So I have 1 ELK server setup and working just fine IP is 172.16.40.28. We  
> > wanted to build a second one to log different servers and for several  
> > reasons keep the data seperate. So I built the new server and setup ELK  
> > again, all seems fine. The IP of the new server is 172.16.40.29. When I go  
> > to the new server IP kibana page I see all the data from the first ELK  
> > server. I have verified that my PC (through netstat) is connecting to .29  
> > and that on .29 through netstat shows me connecting. I tried clearing  
> > cookies and cache - any thoughts or help? when new data comes in I see it  
> > on both servers Kibana pages - so it's almost like Kibana is pointing to  
> > another ES server but I verified it is not in the config.js
> > 
> > Maybe I don't need to build another server but I am new to ELK and  
> > scaling it out in a cluster is over my head at this point
> > 
> > --  
> > Thanks,  
> > Kevin
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/10e468db-e862-4646-b52f-ac7f9b6a7c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/10e468db-e862-4646-b52f-ac7f9b6a7c35%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/10e468db-e862-4646-b52f-ac7f9b6a7c35%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/10e468db-e862-4646-b52f-ac7f9b6a7c35%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/75279414-1276-4aae-a01e-c6f1067550a4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/75279414-1276-4aae-a01e-c6f1067550a4%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:01am UTC](https://discuss.elastic.co/t/strange-issue-with-2-seperate-elk-servers/19814/4 "2017-07-06T01:01:36Z")

</div>


