# What is the best suitable Elasticsearch architecture?

**URL:** <https://discuss.elastic.co/t/what-is-the-best-suitable-elasticsearch-architecture/95394>\
**Category:** Elasticsearch\
**Created:** [August 1, 2017, 6:41pm UTC](https://discuss.elastic.co/t/what-is-the-best-suitable-elasticsearch-architecture/95394 "2017-08-01T18:41:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [August 1, 2017, 6:41pm UTC](https://discuss.elastic.co/t/what-is-the-best-suitable-elasticsearch-architecture/95394/1 "2017-08-01T18:41:10Z")

</div>

Hi, I am planning to use Elasticsearch Cluster with 4 different servers with each Node on one server. Out of which 3 Nodes are Master Eligible and Data Nodes and the other is Coordinating only Node(Kibana is also running on the same machine).

Data ingestion would be 2GB daily. I am planning to have 2 Primary Shards and 1 Replica Shard for each index(Having too many Primary Shards would effect Performance).

**Hardware Specs:**  
CPU - 4x2.2ghz  
Memory- 32gb  
Disk - 600gb

Please let me know if I am missing anything. Your help is highly appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [August 20, 2017, 4:28pm UTC](https://discuss.elastic.co/t/what-is-the-best-suitable-elasticsearch-architecture/95394/2 "2017-08-20T16:28:15Z")

</div>

Hi, Any suggestions please?

---

<div class="post-metadata">

**Author:** ![Gregs](https://avatars.discourse-cdn.com/v4/letter/g/bc79bd/32.png) [@Gregs](https://discuss.elastic.co/u/Gregs)\
**Post date:** [August 21, 2017, 8:46am UTC](https://discuss.elastic.co/t/what-is-the-best-suitable-elasticsearch-architecture/95394/3 "2017-08-21T08:46:13Z")

</div>

Hello Amruth,

It's a wide opened question so that's not a surprised only a few would answer.  
The best architecture is the one which fit to your need.  
Here is from my experience what I can say.  
Your node have everything they need to support an elk solution.

- discovery.zen.ping.unicast.hosts:
- network.host:

> the other is Coordinating only

From the documentation

> **[Node | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html#coordinating-node)**

> Requests like search requests or bulk-indexing requests may involve data held on different data nodes. A search request, for example, is executed in two phases which are coordinated by the node which receives the client request — the coordinating node.

Maybe you are looking for an ingest node:

> **[Ingest pipelines | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html)**

In my point of view, 2Gb a day is not enough to have that kind of process, i would use the 4th node in the cluster.

Regards.

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [August 23, 2017, 2:24pm UTC](https://discuss.elastic.co/t/what-is-the-best-suitable-elasticsearch-architecture/95394/4 "2017-08-23T14:24:50Z")

</div>

Hi Greg,

Thanks for your answer.

I am not using ingest node because there is another node with Logstash which pre-process the documents before they get indexed. Based upon the data ingestion I can always add another node as per your suggestion.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2017, 2:25pm UTC](https://discuss.elastic.co/t/what-is-the-best-suitable-elasticsearch-architecture/95394/5 "2017-09-20T14:25:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
