# Beats & Logstash - What happens if logstash goes offline?

**URL:** <https://discuss.elastic.co/t/beats-logstash-what-happens-if-logstash-goes-offline/230423>\
**Category:** Beats\
**Created:** [April 29, 2020, 6:39pm UTC](https://discuss.elastic.co/t/beats-logstash-what-happens-if-logstash-goes-offline/230423 "2020-04-29T18:39:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ric878](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ric878/32/67387_2.png) [@Ric878](https://discuss.elastic.co/u/Ric878)\
**Post date:** [April 29, 2020, 6:39pm UTC](https://discuss.elastic.co/t/beats-logstash-what-happens-if-logstash-goes-offline/230423/1 "2020-04-29T18:39:26Z")

</div>

I've setup an elasticsearch cluster with 3 Elasticsearch nodes, 1 Kibana, 1 Logstash. Everything is working as expected with one exception.

I currently have my Beats (metric, file, etc.) sending log data to my Logstash node. My question is, if I have to take the Logstash nodes down for maintenance, upgrade, unexpected crash, etc., what happens to the log data that the beats are collecting?

I tried to simulate this by bringing logstash offline for 30 minutes, then bringing it back online. I ended up with a 30 minute gap in metricbeat data but actually got all the filebeat data. Is this expected behaviour? Is there a way to modify this and have metricbeat behave like filebeat in this respect?

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [April 29, 2020, 6:54pm UTC](https://discuss.elastic.co/t/beats-logstash-what-happens-if-logstash-goes-offline/230423/2 "2020-04-29T18:54:43Z")

</div>

You have several alternatives:

- Use the [file spool queue](https://www.elastic.co/guide/en/beats/metricbeat/current/configuring-internal-queue.html#configuration-internal-queue-spool) on Metricbeat (beta!)
- You can use a queueing system as output before reaching Logstash (Kafka, Redis...) using the [supported outputs](https://www.elastic.co/guide/en/beats/metricbeat/current/configuring-output.html) & Logstash inputs
- Configure Metricbeat to write to file and use a Filebeat to send the files to Logstash

---

<div class="post-metadata">

**Author:** ![Ric878](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ric878/32/67387_2.png) [@Ric878](https://discuss.elastic.co/u/Ric878)\
**Post date:** [April 29, 2020, 7:10pm UTC](https://discuss.elastic.co/t/beats-logstash-what-happens-if-logstash-goes-offline/230423/3 "2020-04-29T19:10:33Z")

</div>

Thanks so much for the quick response. This is exactly what I was looking for.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2020, 9:10pm UTC](https://discuss.elastic.co/t/beats-logstash-what-happens-if-logstash-goes-offline/230423/4 "2020-05-27T21:10:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
