# Can Lumberjack plugin ensure 100% delivery guarantee?

**URL:** <https://discuss.elastic.co/t/can-lumberjack-plugin-ensure-100-delivery-guarantee/130461>\
**Category:** Logstash\
**Created:** [May 3, 2018, 1:34pm UTC](https://discuss.elastic.co/t/can-lumberjack-plugin-ensure-100-delivery-guarantee/130461 "2018-05-03T13:34:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [May 3, 2018, 1:34pm UTC](https://discuss.elastic.co/t/can-lumberjack-plugin-ensure-100-delivery-guarantee/130461/1 "2018-05-03T13:34:51Z")

</div>

Hi,

I am using http input and output plugins to transfer messages from one logstash to another logstash(this logstash send messages to Elasticsearch using elasticsearch plugin). I see nearly 20% of message loss and also first Logstash has some errors like

`[HTTP Output Failure] Encountered non-2xx HTTP code 502 {:response_code=>502`

I feel like there are issues with http plugin and wanted to migrate touse Lumberjack plugin. So can someone please say if Lumberjack delivery is 100% guaranteed?

Also is there any way we can know if Logstash is dropping messages(by saving them on local file)?

Thanks

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [May 6, 2018, 3:58am UTC](https://discuss.elastic.co/t/can-lumberjack-plugin-ensure-100-delivery-guarantee/130461/2 "2018-05-06T03:58:16Z")

</div>

Hi,

I've posted lot of questions related to http, tcp, udp input/output plugins, but I didn't get any detailed information on this.

I read somewhere that udp input plugin is not reliable, it helps a lot if you can maintain information on what is reliable and what is not.

Please shed some light on this.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![nikhil.k](https://avatars.discourse-cdn.com/v4/letter/n/5daacb/32.png) [@nikhil.k](https://discuss.elastic.co/u/nikhil.k)\
**Post date:** [May 7, 2018, 10:52am UTC](https://discuss.elastic.co/t/can-lumberjack-plugin-ensure-100-delivery-guarantee/130461/3 "2018-05-07T10:52:25Z")

</div>

Hi @amruth

> [@amruth](#):
>
> I read somewhere that udp input plugin is not reliable, it helps a lot if you can maintain information on what is reliable and what is not.

I think non reliability of udp input plugin would mean as follows:-  
Consider the scenario in which logstash/its hosts is terminated abnormally or if logstash is overloaded?

In this scenario, there would be data loss, as logstash input plugins (upd, tcp and many others) do not use request-response protocol. There would be no acknowledge receipt to the sender about the failure.

For eg. there are two machine(A & B).  
machine A - sender  
machine B - logstash

Machine A sends data to the machine B which is initially UP. Now suppose machine B gets down during data transfer. Here, sender would not be knowing the current status (down) of machine B and will continue to send the data, which arise to the problem of data loss.

The above limitation can be avoided by configuring persistent queue in logstash, which will provide the data durability in events of abnormal shutdown of Logstash or its host, ensuring at least once delivery.

In detail, please refer to the link:- [Scaling Elasticsearch, Kibana, Beats, and Logstash | Elastic Blog](https://www.elastic.co/blog/small-medium-or-large-scaling-elasticsearch-and-evolving-the-elastic-stack-to-fit)

Regards  
Nikhil Kapoor

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2018, 10:52am UTC](https://discuss.elastic.co/t/can-lumberjack-plugin-ensure-100-delivery-guarantee/130461/4 "2018-06-04T10:52:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
