# Configuring Logstash to Use Dead Letter Queues

**URL:** <https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892>\
**Category:** Logstash\
**Created:** [February 21, 2018, 4:12pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892 "2018-02-21T16:12:40Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 21, 2018, 4:12pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892/1 "2018-02-21T16:12:40Z")

</div>

Per [Configuring Logstash to Use Dead Letter Queues](https://www.elastic.co/guide/en/logstash/current/dead-letter-queues.html#configuring-dlq):

> Dead letter queues are disabled by default. To enable dead letter queues, set the dead\_letter\_queue\_enable option in the logstash.yml settings file:
> 
> dead\_letter\_queue.enable: true

I enabled option via [Configuring Logstash for Docker | Logstash Reference [6.2] | Elastic](https://www.elastic.co/guide/en/logstash/current/docker-config.html#docker-env-config):

```
# grep DEAD_LETTER_QUEUE.ENABLE docker-compose.override.yml 
                        - DEAD_LETTER_QUEUE.ENABLE=true
#

```

[Processing Events in the Dead Letter Queue](https://www.elastic.co/guide/en/logstash/current/dead-letter-queues.html#processing-dlq-events)

```
# cat pipeline/10-input-dead_letter_queue.conf 
input {
	dead_letter_queue {
		path => "/usr/share/logstash/data/dead_letter_queue/main"
	}
}
# 

```

and now, whenever I start logstash, I'm getting following errors:

```
logstash11 | [2018-02-21T16:04:40,494][ERROR][logstash.pipeline] Error registering plugin {:pipeline_id=>"main", :plugin=>"<LogStash::Inputs::DeadLetterQueue path=>\"/usr/share/logstash/data/dead_letter_queue/main\", id=>\"dbb698a5fbc95fc57c4d4035e6aea289b838d574786111ae96ee36dc6438b7fc\", enable_metric=>true, codec=><LogStash::Codecs::Plain id=>\"plain_9c74df7f-06ba-46db-a683-a034892e1b8c\", enable_metric=>true, charset=>\"UTF-8\">, pipeline_id=>\"main\", commit_offsets=>true>", :error=>"/usr/share/logstash/data/dead_letter_queue/main/main", :thread=>"#<Thread:0x749b0f73 run>"}
logstash11 | [2018-02-21T16:04:40,886][ERROR][logstash.pipeline] Pipeline aborted due to error {:pipeline_id=>"main", :exception=>java.nio.file.NoSuchFileException: /usr/share/logstash/data/dead_letter_queue/main/main, :backtrace=>["sun.nio.fs.UnixException.translateToIOException(sun/nio/fs/UnixException.java:86)", "sun.nio.fs.UnixException.asIOException(sun/nio/fs/UnixException.java:111)", "sun.nio.fs.LinuxWatchService$Poller.implRegister(sun/nio/fs/LinuxWatchService.java:246)", "sun.nio.fs.AbstractPoller.processRequests(sun/nio/fs/AbstractPoller.java:260)", "sun.nio.fs.LinuxWatchService$Poller.run(sun/nio/fs/LinuxWatchService.java:364)", "java.lang.Thread.run(java/lang/Thread.java:748)"], :thread=>"#<Thread:0x749b0f73 run>"}
logstash11 | [2018-02-21T16:04:40,909][ERROR][logstash.agent] Failed to execute action {:id=>:main, :action_type=>LogStash::ConvergeResult::FailedAction, :message=>"Could not execute action: LogStash::PipelineAction::Create/pipeline_id:main, action_result: false", :backtrace=>nil}

```

* * *

second part of my issue is: I'd like for events from DLQ to be display via:

```
output {
  stdout {
    codec => rubydebug { metadata => true }
  }
}

```

however, I already have output as part of pipeline, how would I display _only_ events from DLQ?

Please advise.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2018, 5:52pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892/2 "2018-02-21T17:52:48Z")

</div>

You have told logstash that the DLQs are under /usr/share/logstash/data/dead\_letter\_queue/main, and you have not given it a pipeline id, so it is going to default to main for that, and look for /usr/share/logstash/data/dead\_letter\_queue/main/main. The error is telling you that directory does not exist.

I do not understand the second part of your question. If the input in your DLQ pipeline is the DLQ then the pipeline will only process events from the DLQ.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 21, 2018, 8:34pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892/3 "2018-02-21T20:34:45Z")

</div>

ahh, I see `main/main`, so I tweak it a bit:

```
# cat pipeline/10-input-dead_letter_queue.conf 
input {
	dead_letter_queue {
		path => "/usr/share/logstash/data/dead_letter_queue"
	}
}
# 

```

and now logstash's log showing me following:

> logstash11 | [2018-02-21T20:25:04,224][WARN][org.logstash.common.io.DeadLetterQueueWriter] Event previously submitted to dead letter queue. Skipping...

* * *

"A picture is worth ten thousand words")

 ![pipeline](https://us1.discourse-cdn.com/elastic/original/3X/9/2/92d6aaeca9eccbb80c7026467460d9cad2fbefd7.png)

my output:

```
# grep -v ^# pipeline/30-output-elasticsearch.conf 
output {
	if [tags] {
		elasticsearch {
			hosts => "elasticsearch:9200"
			user => "elastic"
			password => "X"
			manage_template => false
			index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
			document_type => "%{[@metadata][type]}"
		}
	} else {
		elasticsearch {
			hosts => "elasticsearch:9200"
			user => "elastic"
			password => "X"
		}
	}
}
# 

```

for events from DLQ, I'd like to use:

> output { codec =\> rubydebug }

how can I accomplish that? assign id for DLQ and use if statement in output to redirect to alternative output?

Please advise.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2018, 9:13pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892/4 "2018-02-21T21:13:16Z")

</div>

> [@alexus](#):
>
> assign id for DLQ and use if statement in output to redirect to alternative output?

That sounds entirely reasonable.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 21, 2018, 9:31pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892/5 "2018-02-21T21:31:27Z")

</div>

input:

```
# cat pipeline/10-input-dead_letter_queue.conf 
input {
	dead_letter_queue {
		id => "dlq"
		path => "/usr/share/logstash/data/dead_letter_queue"
	}
}
# 

```

output:

```
# cat pipeline/30-output-elasticsearch.conf | tail -6
	} else if ["dlq"] == [id] {
		stdout {
			codec => rubydebug { metadata => true }
		}
	}
}
# 

```

output is wrong and breaks logstash(

Do you think you can give me a hand here, please (with cherry on the top)?)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2018, 9:40pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892/6 "2018-02-21T21:40:09Z")

</div>

> [@alexus](#):
>
> else if ["dlq"] == [id]

Instead of setting id (since I do not know whether you can reference that the way you want to), try adding a tag

```auto
tags => ["dlq"]

```

and then checking for that

```auto
} else if "dlq" in [tags] {

```

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 21, 2018, 9:54pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892/7 "2018-02-21T21:54:27Z")

</div>

hmm, I tried and even though logstash still produces following messages:

> logstash11 | [2018-02-21T21:52:43,054][WARN][org.logstash.common.io.DeadLetterQueueWriter] Event previously submitted to dead letter queue. Skipping...

I don't see anything in stdout (codec=\>rubydebug)...

 ![pipeline2](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d6ca48ec15be382611a4e9df58d4cafde21aff8f.png)

Any ideas?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2018, 10:15pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892/8 "2018-02-21T22:15:05Z")

</div>

> [@alexus](#):
>
> Event previously submitted to dead letter queue. Skipping...

logstash knows it has processed the item that is in the DLQ, so it is not going to reprocess it unless you takes steps to make that happen. There is a sincedb\_path parameter to the DLQ input that tells it which file to use to keep track of which queue items have been processed. You appear to be using the default. You could delete that file, which should cause logstash to start at the beginning of the queue again (and recreate the sincedb).

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 22, 2018, 4:00am UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892/9 "2018-02-22T04:00:09Z")

</div>

I'm using Docker container for Logstash and I don't preserve sincedb while restarting container. Regardless, I'm not interested in old events, all I care about now and I can't get current events to stdout( above message is for new event...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2018, 4:00am UTC](https://discuss.elastic.co/t/configuring-logstash-to-use-dead-letter-queues/120892/10 "2018-03-22T04:00:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
