# Two-node graylog+elasticsearch failover cluster

**URL:** <https://discuss.elastic.co/t/two-node-graylog-elasticsearch-failover-cluster/271355>\
**Category:** Elasticsearch\
**Created:** [April 27, 2021, 10:11am UTC](https://discuss.elastic.co/t/two-node-graylog-elasticsearch-failover-cluster/271355 "2021-04-27T10:11:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dunhillers](https://avatars.discourse-cdn.com/v4/letter/d/779978/32.png) [@dunhillers](https://discuss.elastic.co/u/dunhillers)\
**Post date:** [April 27, 2021, 10:11am UTC](https://discuss.elastic.co/t/two-node-graylog-elasticsearch-failover-cluster/271355/1 "2021-04-27T10:11:04Z")

</div>

Hi, I have deployed graylog+elastic on two servers (Centos 7.8). **The goal** : to create a failover cluster of two nodes with support for index replication. So that if one of the nodes falls, the indexes continue to be written on the second node and the indexes are replicated.  
**Build:** Logs from 12 third-party servers are written by syslog to the Indexes of elastic server #1 and replicated to server #2.  
**My problem:** When server # 1, which is the master, is unavailable, elastic disappears on the second one and the indexes in graylog become unavailable and new messages are not written until node #1 is restored. (it turns out that the bundle is not fault-tolerant ).  
Please help me to solve this problem.

_show me your ready-made configs with fault-tolerant settings. If necessary, I can show my configs .yum .conf_

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 27, 2021, 10:17am UTC](https://discuss.elastic.co/t/two-node-graylog-elasticsearch-failover-cluster/271355/2 "2021-04-27T10:17:03Z")

</div>

You can not build a highly available cluster with just 2 nodes. You will need to add a third node, even if this is a master-only node that does not hold data. That would give you the 3 master-eligible nodes required in order to be able to cope with one node going down.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [April 27, 2021, 10:53am UTC](https://discuss.elastic.co/t/two-node-graylog-elasticsearch-failover-cluster/271355/3 "2021-04-27T10:53:14Z")

</div>

Linking the [reference manual pages](https://www.elastic.co/guide/en/elasticsearch/reference/current/high-availability-cluster-small-clusters.html#high-availability-cluster-design-two-nodes) on this subject, noting particularly:

> Because it’s not resilient to failures, we do not recommend deploying a two-node cluster in production.

---

<div class="post-metadata">

**Author:** ![dunhillers](https://avatars.discourse-cdn.com/v4/letter/d/779978/32.png) [@dunhillers](https://discuss.elastic.co/u/dunhillers)\
**Post date:** [April 27, 2021, 11:18am UTC](https://discuss.elastic.co/t/two-node-graylog-elasticsearch-failover-cluster/271355/4 "2021-04-27T11:18:42Z")

</div>

Thank you for your reply friends. It turns out that a bundle of two nodes can only survive the fall of the secondary node (Datanode), but if the first node with the master role falls, then the second node does not become the master, do I understand you correctly? In the opposite direction, it will work, if the secondary node falls, we will not lose the indexes, only the performance will decrease?

---

<div class="post-metadata">

**Author:** ![dunhillers](https://avatars.discourse-cdn.com/v4/letter/d/779978/32.png) [@dunhillers](https://discuss.elastic.co/u/dunhillers)\
**Post date:** [April 27, 2021, 11:24am UTC](https://discuss.elastic.co/t/two-node-graylog-elasticsearch-failover-cluster/271355/5 "2021-04-27T11:24:48Z")

</div>

Thank you David, I read this guide! But it remains unclear to me when exactly we lose the Indexes.. When we lose the first node with the master, or in both cases, will automatically assign the secondary node with the Data node role, the master role when the primary node is not available.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 27, 2021, 11:29am UTC](https://discuss.elastic.co/t/two-node-graylog-elasticsearch-failover-cluster/271355/6 "2021-04-27T11:29:17Z")

</div>

Yes, that is correct. If you lose your only master node you will lose the data and need to recreate the cluster and restore from snapshot using the snapshot/restore API. I would recommend making both your nodes master eligible and adding a small master only node.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2021, 11:29am UTC](https://discuss.elastic.co/t/two-node-graylog-elasticsearch-failover-cluster/271355/7 "2021-05-25T11:29:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
