# Use master/data or cordinating node for search?

**URL:** <https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127>\
**Category:** Elasticsearch\
**Created:** [July 10, 2026, 2:24pm UTC](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127 "2026-07-10T14:24:33Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 10, 2026, 2:24pm UTC](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127/1 "2026-07-10T14:24:33Z")

</div>

I have six data node, three master and two coordinating (which is also kibana)

I am setting up proxy in front.

for elk:5601 is easy as it is just kibana.

for elk:9200 should I use coordinating nodes or master node or data node?

`balance leastconn`  
`server elkc1 <IP>:9200 check weight 1`  
`server elkc2 <IP>:9200 check weight 1`

everyone for writing and search going to use elk:9200 either from python and/or logstash

or should I setup two separate thing?

elk\_search:9200 -\> different server

elk\_write:9200 -\> different server

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 10, 2026, 2:56pm UTC](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127/2 "2026-07-10T14:56:19Z")

</div>

Hi @elasticforme

First Do not use the Masters.

We could have a long discussion on why you do or do not need coordinating nodes.

If they are pure coordinating nodes I.e do not have ingest role and you use ingest pipelines then think of the a search / read nodes..  
Note kibana dev tool can still POST data etc.

And write to the data nodes...

AND / OR

Even if you have coordinating nodes to support kibana you can also read / write to data nodes.

So the question comes

Why do need coordinator nodes.. it's kinda and old pattern...yup it is in the docs, but they are not as often used these days.. still fine for Kibans isolation but just adds more to manage.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 10, 2026, 3:11pm UTC](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127/3 "2026-07-10T15:11:52Z")

</div>

Allright master is out of question now.

> [@stephenb](#):
>
> Why do need coordinator nodes.. it's kinda and old pattern...yup it is in the docs, but they are not as often used these days.. still fine for Kibans isolation but just adds more to manage.

these two node are just kibana and hence I setup elastic on it as well and bind kibana to itself.

```auto
# cat /etc/kibana/kibana.yml |grep -v ^# |sed '/^$/d'
server.port: 5601
server.host: "elkc1"
server.name: "elkc1"
elasticsearch.hosts: ["http://elkc1:9200"]
elasticsearch.username: "kibana_system"
elasticsearch.password: "<password>"

```

```auto
# grep node.role /etc/elasticsearch/elasticsearch.yml

node.roles: []

```

in your suggestion just add all six datanodes for search/write

like elk:9200 -\> all six nodes ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 10, 2026, 3:14pm UTC](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127/4 "2026-07-10T15:14:56Z")

</div>

> [@elasticforme](#):
>
> these two node are just kibana and hence I setup elastic on it as well and bind kibana to itself.

They will add unnecessary burden to the cluster, specially for a small cluster where there is no need for coordinating nodes.

Just point to the data nodes, if you have data tiering like hot and warm nodes, point to the hot nodes.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 10, 2026, 3:16pm UTC](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127/5 "2026-07-10T15:16:34Z")

</div>

sorry forgot to mention - this is busy cluster not small. ingesting millions of record daily and searching as well.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 10, 2026, 3:28pm UTC](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127/6 "2026-07-10T15:28:28Z")

</div>

> [@elasticforme](#):
>
> sorry forgot to mention - this is busy cluster not small. ingesting millions of record daily and searching as well.

Yeah, but in terms of Elasticsearch this would be considered a small cluster, the coordinating nodes could have more impact than help here as they will add unnecessary latency as all requests need to pass through them.

I would remove them and point directly to the data nodes.

If you do not have data tiering, you can put all six nodes behind the LB to make it easier.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 10, 2026, 4:12pm UTC](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127/7 "2026-07-10T16:12:12Z")

</div>

alright great.

master exclude from all.

5601 -\> two kibana

9200 -\> six data node (all hot)

resource wise I should be ok as I have 90gig ram, 20 core and nvme as storage for each datanode.

---

<div class="post-metadata">

**Author:** ![cartergray234](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cartergray234/32/147857_2.png) [@cartergray234](https://discuss.elastic.co/u/cartergray234)\
**Post date:** [July 11, 2026, 11:00pm UTC](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127/8 "2026-07-11T23:00:52Z")

</div>

Use the coordinating nodes behind your load balancer. Avoid sending client traffic to the master nodes, as they should handle cluster management only. Separate `elk_search` and `elk_write` endpoints are only worth it if you have heavy search and indexing workloads.
