# Dead letter queue not working with logtash output mongo

**URL:** <https://discuss.elastic.co/t/dead-letter-queue-not-working-with-logtash-output-mongo/316030>\
**Category:** Logstash\
**Created:** [October 7, 2022, 5:05am UTC](https://discuss.elastic.co/t/dead-letter-queue-not-working-with-logtash-output-mongo/316030 "2022-10-07T05:05:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![van\_le1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/van_le1/32/111778_2.png) [@van\_le1](https://discuss.elastic.co/u/van_le1)\
**Post date:** [October 7, 2022, 5:05am UTC](https://discuss.elastic.co/t/dead-letter-queue-not-working-with-logtash-output-mongo/316030/1 "2022-10-07T05:05:53Z")

</div>

Hi everyone,

I intend to use dead letter queue on log event failure from sending log into mongodb use logtash.  
My config includes:

> logtash.yml

```auto
http.host: "0.0.0.0"

pipeline.batch.delay: 10

pipeline.batch.size: 10

pipeline.ecs_compatibility: disabled

dead_letter_queue.enable: true

```

> pipelines.yml

```auto
- pipeline.id: backup_elastics
  pipeline.ecs_compatibility: disabled
  path.config: "/usr/share/logstash/pipeline/dead-letter-queue.conf"

- pipeline.id: "read-file-log"
  pipeline.ecs_compatibility: disabled
  path.config: "/usr/share/logstash/pipeline/read-file.conf"

```

with config 2 pipelines, one for send log into mongodb

```auto
input{
    file {
        type => "dummylog"
        path => ["/home/data/*.log"]
    }
}

output{    
    if [type] == "dummylog" {
      mongodb {
        collection => "logtash_mongodb"
        database => "dmp_log"
        uri => "mongodb://logtash:logtash@mongodb:27017/dmp_log"
        codec => "json"
      }
    }
    stdout {
      codec => rubydebug
    }
}

```

the second will write into elastics if any failed log event

```auto
input {
  dead_letter_queue {
    id => "backup_elastics"
    pipeline_id => "read-file-log"
    commit_offsets => true
    path => "/usr/share/logstash/data/dead_letter_queue/"
  }
}

output {
  elasticsearch {
    hosts => ["elasticsearch:9200"]
    index => "logs-%{+YYYY.MM.dd}"
    manage_template => false
  }
  stdout {
    codec => rubydebug
  }
}

```

but when mongo got problem, it's not send into the dead letter queue.

```auto
logtash-mongo-logstash-1 | [WARN] 2022-10-07 04:59:56.849 [[read-file-log]>worker1] mongodb - Failed to send event to MongoDB, retrying in 3 seconds {:event=>#<LogStash::Event:0x31ec7696>, :exception=>#<Mongo::Error::NoServerAvailable: No server is available matching preference: #<Mongo::ServerSelector::Primary:0x7a355ad8 @tag_sets=[], @server_selection_timeout=30, @options={:database=>"dmp_log", :user=>"logtash", :password=>"logtash"}>>}
logtash-mongo-logstash-1

```

I'm using logtash 7.17.6, logtash output mongodb version 3.1.5.  
So any config above wrong? or how can i catch the error from first pipeline(logtash-mongodb) to process failed event?

Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 7, 2022, 3:44pm UTC](https://discuss.elastic.co/t/dead-letter-queue-not-working-with-logtash-output-mongo/316030/2 "2022-10-07T15:44:35Z")

</div>

According to the [documentation](https://www.elastic.co/guide/en/logstash/current/dead-letter-queues.html#dead-letter-how) the DLQ is only supported by the elasticsearch output. Any output could be modified to use a [dlq\_writer](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/f69df560b89bdf02829bc2fa33fff5c867f07512/lib/logstash/plugin_mixins/elasticsearch/common.rb#L209), but that has only been done for the elasticsearch output.

---

<div class="post-metadata">

**Author:** ![van\_le1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/van_le1/32/111778_2.png) [@van\_le1](https://discuss.elastic.co/u/van_le1)\
**Post date:** [October 10, 2022, 1:04am UTC](https://discuss.elastic.co/t/dead-letter-queue-not-working-with-logtash-output-mongo/316030/3 "2022-10-10T01:04:20Z")

</div>

yes, thank you  
i miss the note below

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2022, 1:05am UTC](https://discuss.elastic.co/t/dead-letter-queue-not-working-with-logtash-output-mongo/316030/4 "2022-11-07T01:05:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
