# Are the logs lost if elastic search down

**URL:** <https://discuss.elastic.co/t/are-the-logs-lost-if-elastic-search-down/279561>\
**Category:** Elasticsearch\
**Created:** [July 25, 2021, 12:45pm UTC](https://discuss.elastic.co/t/are-the-logs-lost-if-elastic-search-down/279561 "2021-07-25T12:45:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Post date:** [July 25, 2021, 12:45pm UTC](https://discuss.elastic.co/t/are-the-logs-lost-if-elastic-search-down/279561/1 "2021-07-25T12:45:13Z")

</div>

Hello every body,

I have a question about the fate of the logs when the elasticsearch is down. if the logs are lost during the inactivity of elasticsearch, how can we get around this problem?

Best regards,

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 25, 2021, 2:01pm UTC](https://discuss.elastic.co/t/are-the-logs-lost-if-elastic-search-down/279561/2 "2021-07-25T14:01:50Z")

</div>

Elastic and other components can be configured so logs are not lost, but the techniques vary by logging method.

Filebeat, for example is pretty easy, if filebeat can't send events, it will wait until it can, so until the logs are deleted on the sending host, they can still be sent. Logstash has the option of persistent queues, so it can store events (limited on disk space of course).

You will have to design persistent log methods for each specific case. I use logstash (multiple instances) persistent queues for syslog type events but let 'beats wait till they can send relying on the sending hosts to store the events.

---

<div class="post-metadata">

**Author:** ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Post date:** [July 25, 2021, 3:07pm UTC](https://discuss.elastic.co/t/are-the-logs-lost-if-elastic-search-down/279561/3 "2021-07-25T15:07:33Z")

</div>

Hello rugenl,  
Thanks for replaying.

> [@rugenl](#):
>
> You will have to design persistent log methods for each specific case.

After a simple search on the official ELK website I found the limits below for the diffinition of persistent queue logs:

> - Input plugins that do not use a request-response protocol cannot be protected from data loss. For example: tcp, udp, zeromq push+pull, and many other inputs do not have a mechanism to acknowledge receipt to the sender. Plugins such as beats and http, which **do** have an acknowledgement capability, are well protected by this queue.

what I understood in the case of using syslog for example to send logs this method will not be useful.

Best regerds

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 25, 2021, 6:04pm UTC](https://discuss.elastic.co/t/are-the-logs-lost-if-elastic-search-down/279561/4 "2021-07-25T18:04:39Z")

</div>

We direct syslog to a network load balancer backed by multiple site, multi server logstash with persistent queues. A lot of it is sent UDP, so it doesn't have assured delivery anyway.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2021, 6:04pm UTC](https://discuss.elastic.co/t/are-the-logs-lost-if-elastic-search-down/279561/5 "2021-08-22T18:04:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
