# Correct nodes to send logs

**URL:** <https://forum.opensearch.org/t/correct-nodes-to-send-logs/5311>\
**Category:** Open Source Elasticsearch and Kibana\
**Created:** [March 12, 2021, 12:57pm UTC](https://forum.opensearch.org/t/correct-nodes-to-send-logs/5311 "2021-03-12T12:57:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darrell](https://avatars.discourse-cdn.com/v4/letter/d/54ee81/32.png) [@Darrell](https://forum.opensearch.org/u/Darrell)\
**Post date:** [March 12, 2021, 12:57pm UTC](https://forum.opensearch.org/t/correct-nodes-to-send-logs/5311/1 "2021-03-12T12:57:05Z")

</div>

Hi all,

I have an OD EFK cluster in kubernettes with the following setup:  
Version: opendistro-for-elasticsearch:1.12.0  
5x es-client nodes  
5x es-data nodes  
3x es-master nodes  
fluent-bit deamon set

For clarity sake, when sending logs to the cluster do you send them to the client, master or data nodes? When I send to client nodes I get a lot of the following errors:

[error] [upstream] connection #82 to opendistro-es-client-service.logging.svc.cluster.local:9200 timed out after 10 seconds

Could someone please clarify the correct set of nodes to send the logs to

Kind Regards

---

<div class="post-metadata">

**Author:** ![Darrell](https://avatars.discourse-cdn.com/v4/letter/d/54ee81/32.png) [@Darrell](https://forum.opensearch.org/u/Darrell)\
**Post date:** [March 12, 2021, 1:58pm UTC](https://forum.opensearch.org/t/correct-nodes-to-send-logs/5311/2 "2021-03-12T13:58:16Z")

</div>

I would assume that it all depends on if node.ingest=true or not on those nodes.
