# System Requirements for ElasticSearch stack

**URL:** <https://discuss.elastic.co/t/system-requirements-for-elasticsearch-stack/19108>\
**Category:** Elasticsearch\
**Created:** [August 6, 2014, 4:02am UTC](https://discuss.elastic.co/t/system-requirements-for-elasticsearch-stack/19108 "2014-08-06T04:02:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gopinath\_Nallappan](https://avatars.discourse-cdn.com/v4/letter/g/da6949/32.png) [@Gopinath\_Nallappan](https://discuss.elastic.co/u/Gopinath_Nallappan)\
**Post date:** [August 6, 2014, 4:02am UTC](https://discuss.elastic.co/t/system-requirements-for-elasticsearch-stack/19108/1 "2014-08-06T04:02:59Z")

</div>

Hello all,

I'm new to the ELK stack. I will be logging Windows Events, Syslogs from  
firewalls, routers etc into my elasticsearch.

I am expecting daily data of around 2GB to be logged into my elasticsearch  
server. I will be creating indices on daily or weekly basis.

And my logs are going to be stored for atleast a year online and offline  
after that.

I have been looking around and also searched this forum, but I was not able  
to find a definitive guide that explained how to design the architecture -  
RAM, # of CPU cores, # of Elastcisearch nodes and shards / node.

The system will be mainly used for logging purposes only. So there won't be  
that many concurrent users.

Appreciate any pointers on best practices in setting up the Elasticsearch  
deployment.

Thanks,  
Gopinath

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [August 6, 2014, 9:19am UTC](https://discuss.elastic.co/t/system-requirements-for-elasticsearch-stack/19108/2 "2014-08-06T09:19:34Z")

</div>

There is no "one size fits all", no strict measure for RAM, CPU cores,  
shard/node. This all depends on your testing results and your requirements.  
Do not trust other test results more than your own.

You can index 2G with Elasticsearch in a few minutes, using commodity  
hardware. Do not expect problems here.

For sizing, you should also take into consideration the total volume you  
have to keep (for disk space setup) and how much query workload you need to  
serve (for replica). The number of users is a hint, but it depends on the  
type of query too (filters, aggregations, etc.)

For fault tolerance, you should take into consideration the availability of  
the system. If you don't care, one node might be sufficient, but production  
should at least use three nodes, for better fault tolerance.

Jörg

On Wed, Aug 6, 2014 at 6:02 AM, Gopinath Nallappan \<  
[gopinathnallappan@gmail.com](mailto:gopinathnallappan@gmail.com)\> wrote:

> Hello all,
> 
> I'm new to the ELK stack. I will be logging Windows Events, Syslogs from  
> firewalls, routers etc into my elasticsearch.
> 
> I am expecting daily data of around 2GB to be logged into my elasticsearch  
> server. I will be creating indices on daily or weekly basis.
> 
> And my logs are going to be stored for atleast a year online and offline  
> after that.
> 
> I have been looking around and also searched this forum, but I was not  
> able to find a definitive guide that explained how to design the  
> architecture - RAM, # of CPU cores, # of Elastcisearch nodes and shards /  
> node.
> 
> The system will be mainly used for logging purposes only. So there won't  
> be that many concurrent users.
> 
> Appreciate any pointers on best practices in setting up the Elasticsearch  
> deployment.
> 
> Thanks,  
> Gopinath
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAKdsXoH6aNsZht5WSHnNRqSH6jiNngwHQZnR%2BY96W6\_DtwEJXg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAKdsXoH6aNsZht5WSHnNRqSH6jiNngwHQZnR%2BY96W6_DtwEJXg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Jaguar](https://avatars.discourse-cdn.com/v4/letter/j/4af34b/32.png) [@Jaguar](https://discuss.elastic.co/u/Jaguar)\
**Post date:** [August 7, 2014, 1:09am UTC](https://discuss.elastic.co/t/system-requirements-for-elasticsearch-stack/19108/3 "2014-08-07T01:09:11Z")

</div>

I have found quite a few simliar emails about capacity planning. Although  
it make sense that there are a lot of variables/factors, it would be great  
for new users to have some sort of baseline, which could be simple , just  
single type of indices, not too heavy load. Maybe there are already  
blogs/articles covering thus topic, but worth a pointer in official  
document.

My 2c

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAP0hgQ06eO3%2BfzjTLrN-xMybFSopC%3DkBbPDd%2BKr-qUc2qpuJTw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAP0hgQ06eO3%2BfzjTLrN-xMybFSopC%3DkBbPDd%2BKr-qUc2qpuJTw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vjbangis](https://avatars.discourse-cdn.com/v4/letter/v/9e8a1a/32.png) [@vjbangis](https://discuss.elastic.co/u/vjbangis)\
**Post date:** [August 8, 2014, 1:48am UTC](https://discuss.elastic.co/t/system-requirements-for-elasticsearch-stack/19108/4 "2014-08-08T01:48:35Z")

</div>

Thanks Gopinath!

Hi Jörg,

\*For fault tolerance, you should take into consideration the availability

> of the system. If you don't care, one node might be sufficient, but  
> production should at least use three nodes, for better fault tolerance.\*

Is the three nodes like c3.large, each node, or an m3.large or an m3._x_large  
like?

TIA!

On Wednesday, August 6, 2014 5:19:42 PM UTC+8, Jörg Prante wrote:

> There is no "one size fits all", no strict measure for RAM, CPU cores,  
> shard/node. This all depends on your testing results and your requirements.  
> Do not trust other test results more than your own.
> 
> You can index 2G with Elasticsearch in a few minutes, using commodity  
> hardware. Do not expect problems here.
> 
> For sizing, you should also take into consideration the total volume you  
> have to keep (for disk space setup) and how much query workload you need to  
> serve (for replica). The number of users is a hint, but it depends on the  
> type of query too (filters, aggregations, etc.)
> 
> For fault tolerance, you should take into consideration the availability  
> of the system. If you don't care, one node might be sufficient, but  
> production should at least use three nodes, for better fault tolerance.
> 
> Jörg
> 
> On Wed, Aug 6, 2014 at 6:02 AM, Gopinath Nallappan \<[gopinath...@gmail.com](mailto:gopinath...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > Hello all,
> > 
> > I'm new to the ELK stack. I will be logging Windows Events, Syslogs from  
> > firewalls, routers etc into my elasticsearch.
> > 
> > I am expecting daily data of around 2GB to be logged into my  
> > elasticsearch server. I will be creating indices on daily or weekly basis.
> > 
> > And my logs are going to be stored for atleast a year online and offline  
> > after that.
> > 
> > I have been looking around and also searched this forum, but I was not  
> > able to find a definitive guide that explained how to design the  
> > architecture - RAM, # of CPU cores, # of Elastcisearch nodes and shards /  
> > node.
> > 
> > The system will be mainly used for logging purposes only. So there won't  
> > be that many concurrent users.
> > 
> > Appreciate any pointers on best practices in setting up the Elasticsearch  
> > deployment.
> > 
> > Thanks,  
> > Gopinath
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4357fe8d-2e51-4ef5-921a-bfe07124f6a9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4357fe8d-2e51-4ef5-921a-bfe07124f6a9%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [August 11, 2014, 11:25am UTC](https://discuss.elastic.co/t/system-requirements-for-elasticsearch-stack/19108/5 "2014-08-11T11:25:16Z")

</div>

You can use any machine you want, bare metal, VM, whatever. ES is not bound  
to Amazon EC2 conditions at all. It will depend on your data.

Jörg

On Fri, Aug 8, 2014 at 3:48 AM, vjbangis [jessviray0708@gmail.com](mailto:jessviray0708@gmail.com) wrote:

> Thanks Gopinath!
> 
> Hi Jörg,
> 
> \*For fault tolerance, you should take into consideration the availability
> 
> > of the system. If you don't care, one node might be sufficient, but  
> > production should at least use three nodes, for better fault tolerance.\*
> 
> Is the three nodes like c3.large, each node, or an m3.large or an m3._x_large  
> like?
> 
> TIA!
> 
> On Wednesday, August 6, 2014 5:19:42 PM UTC+8, Jörg Prante wrote:
> 
> > There is no "one size fits all", no strict measure for RAM, CPU cores,  
> > shard/node. This all depends on your testing results and your requirements.  
> > Do not trust other test results more than your own.
> > 
> > You can index 2G with Elasticsearch in a few minutes, using commodity  
> > hardware. Do not expect problems here.
> > 
> > For sizing, you should also take into consideration the total volume you  
> > have to keep (for disk space setup) and how much query workload you need to  
> > serve (for replica). The number of users is a hint, but it depends on the  
> > type of query too (filters, aggregations, etc.)
> > 
> > For fault tolerance, you should take into consideration the availability  
> > of the system. If you don't care, one node might be sufficient, but  
> > production should at least use three nodes, for better fault tolerance.
> > 
> > Jörg
> > 
> > On Wed, Aug 6, 2014 at 6:02 AM, Gopinath Nallappan \<[gopinath...@gmail.com](mailto:gopinath...@gmail.com)
> > 
> > > wrote:
> > 
> > > Hello all,
> > > 
> > > I'm new to the ELK stack. I will be logging Windows Events, Syslogs from  
> > > firewalls, routers etc into my elasticsearch.
> > > 
> > > I am expecting daily data of around 2GB to be logged into my  
> > > elasticsearch server. I will be creating indices on daily or weekly basis.
> > > 
> > > And my logs are going to be stored for atleast a year online and offline  
> > > after that.
> > > 
> > > I have been looking around and also searched this forum, but I was not  
> > > able to find a definitive guide that explained how to design the  
> > > architecture - RAM, # of CPU cores, # of Elastcisearch nodes and shards /  
> > > node.
> > > 
> > > The system will be mainly used for logging purposes only. So there won't  
> > > be that many concurrent users.
> > > 
> > > Appreciate any pointers on best practices in setting up the  
> > > Elasticsearch deployment.
> > > 
> > > Thanks,  
> > > Gopinath
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > 
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%  
> > > [40googlegroups.com](http://40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/23818203-6fe3-49ae-996d-443c2250ea34%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/4357fe8d-2e51-4ef5-921a-bfe07124f6a9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4357fe8d-2e51-4ef5-921a-bfe07124f6a9%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/4357fe8d-2e51-4ef5-921a-bfe07124f6a9%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/4357fe8d-2e51-4ef5-921a-bfe07124f6a9%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAKdsXoEpTe1dZS%3DBYhn6gTTG72wknnHufemTS7unChB%3Dr2xGMw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAKdsXoEpTe1dZS%3DBYhn6gTTG72wknnHufemTS7unChB%3Dr2xGMw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:09am UTC](https://discuss.elastic.co/t/system-requirements-for-elasticsearch-stack/19108/6 "2017-07-06T01:09:35Z")

</div>


