# Which Elasticsearch Node Roles should be connected to Graylog?

**URL:** <https://community.graylog.org/t/which-elasticsearch-node-roles-should-be-connected-to-graylog/26562>\
**Category:** Graylog Central (peer support)\
**Tags:** elastic\
**Created:** [November 16, 2022, 4:10pm UTC](https://community.graylog.org/t/which-elasticsearch-node-roles-should-be-connected-to-graylog/26562 "2022-11-16T16:10:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mobk](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mobk/32/13447_2.png) [@mobk](https://community.graylog.org/u/mobk)\
**Post date:** [November 16, 2022, 4:10pm UTC](https://community.graylog.org/t/which-elasticsearch-node-roles-should-be-connected-to-graylog/26562/1 "2022-11-16T16:10:43Z")

</div>

Hi : ),

I am creating a new multi node installation which look as follows:

- 3 Graylog Nodes
- 3 Elasticsearch Master Nodes
- 1 Elasticsearch Data Node (I am planning to add more data nodes in the future)

Could you tell me please which elasticsearch hosts I should include in the Graylog configuration file?  
Shall I add only elasticsearch master nodes or I should add all nodes (master + data nodes)?

Thank you in advance.

- OS Information: The Graylog/Elasticsearch nodes are running Ubuntu Server 22.04
- Package Version:  
Graylog 4.3  
Elasticsearch 7.10.2

**Helpful Posting Tips:** [Tips for Posting Questions that Get Answers](https://community.graylog.org/t/tips-for-posting-questions-that-get-answers/21828) [Hold down CTRL and link on link to open tips documents in a separate tab]

---

<div class="post-metadata">

**Author:** ![m\_mlk](https://avatars.discourse-cdn.com/v4/letter/m/bbe5ce/32.png) [@m\_mlk](https://community.graylog.org/u/m_mlk)\
**Post date:** [November 17, 2022, 5:01pm UTC](https://community.graylog.org/t/which-elasticsearch-node-roles-should-be-connected-to-graylog/26562/2 "2022-11-17T17:01:05Z")

</div>

Hi @mobk

welcome to the Community! 🙂

I haven’t found any documentation about that while I was setting up our 3x nodes OpenSearch (OS) cluster. WIth that said, our Graylog cluster points to all OS members (master and data roles), and everything works fine.

HTH

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [November 19, 2022, 5:10am UTC](https://community.graylog.org/t/which-elasticsearch-node-roles-should-be-connected-to-graylog/26562/3 "2022-11-19T05:10:46Z")

</div>

Hello && Welocm @mobk

> [@mobk](#):
>
> Could you tell me please which elasticsearch hosts I should include in the Graylog configuration file?

In the documentation [here](https://docs.graylog.org/docs/server-conf#:~:text=subnets%2C%20or%20hosts.-,ELASTICSEARCH,-elasticsearch_hosts%20%3D%20http%3A//node1)  
Basically what I did with 6 node cluster 3 ES & 3 GL/Mongo.  
This was configure on each graylog node.  
.

```auto
elasticsearch_hosts = http://10.10.10.10:9200, http://10.10.10.20:9200, http://10.10.10.30:9200

```

Depending on how the cluster is set up you could use something like this

```auto
http://node1:9200,http://user:password@node2:19200,http://user:password@node3:19200

```

This was only done for ES master nodes since they ingest from Graylogs journal.

Probably a better way would be a load balancer, if you expanding larger then three nodes. It would make this task much easier down the road.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [December 3, 2022, 5:11am UTC](https://community.graylog.org/t/which-elasticsearch-node-roles-should-be-connected-to-graylog/26562/4 "2022-12-03T05:11:40Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
