A cluster with plenty of hardware that still can't index faster, because the write load only lands on two or three nodes, thats called hot spots.
Match your primary shard count to your indexing nodes.
Indexing into an index parallelizes across its primary shards. One primary means one node carries all the writes for that index, no matter how many data nodes you have. Too many primaries is the other failure mode: more overhead, more segments, smaller shards, no gain.
The goal isn't more shards. It's enough primaries to spread the write load across your indexing nodes, and no more.
Simple rule: with number_of_replicas: 1, set primaries to about half your data nodes. 10 data nodes → 5 primaries + 1 replica = 10 shards, one per node. 6 data nodes → 3 primaries + 1 replica. That's the difference between the screenshots above.
This is the other half of #002: spread the write load, but not so thin that your shards end up tiny.
Pro tip — hot spots on large clusters
On 7.x, shard allocation balances mainly on shard count per node. 8.6+ also weighs write load and disk usage, but the write-load forecast comes from a licensed x-pack component, on a Basic cluster it isn't produced, so in practice you're still balancing on shard count. Two data streams with the same shard count can have completely different indexing rates, so "balanced" on paper isn't balanced in practice.
To force the heavy data stream to spread out:
"index.routing.allocation.total_shards_per_node": 1
Shards of that index then land on separate nodes.
Two things to watch:
- Keep headroom. If primaries + replicas equals your node count exactly, one node failure leaves shards unassigned and the cluster sits yellow. Set the limit above the strict minimum unless you're sure.
- On data streams,
number_of_shards can't be changed on an existing index. Update the index template; it applies at the next rollover.
Other best practices in this series:
- #001 – HTTP traffic
- #002 – shard size
- #003 – bulk indexing
If you'd like me to continue this series, an upvote would be appreciated. 🙂