Behavior of Logstash in case of crash in combination with syslog

Hi everyone,

I'm quite new to ELK and want to know Logstash's behavior when it crashs.
Assuming syslog is sending its data to Logstash and then Logstash suddenly crashs. What happens with the data syslog have already sent to Logstash?
Does Logstash something like buffering? Or are the data lost?

Thank you in advance.

Best regards,
Simon

https://www.elastic.co/guide/en/logstash/current/persistent-queues.html

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.