This document provides guidance on sizing Elastic Stack deployments for security use cases. It discusses Elasticsearch internals and computing resources needed for different node roles. It recommends preparing by ingesting sample data and monitoring size and ingestion rates to calculate storage needs. The document also discusses optimizing performance by understanding hardware capabilities, balancing cluster size and costs, and aiming for optimal shard sizes. It suggests using techniques like cross-cluster search, data tiering, and transforms. Guidance is provided on scaling Kibana and the detection engine. Examples are given for calculating storage needs and determining necessary data nodes for small and large deployments.