# Does logstash continue getting log from Kafka if it cannot send log to ELS?

**URL:** <https://discuss.elastic.co/t/does-logstash-continue-getting-log-from-kafka-if-it-cannot-send-log-to-els/255648>\
**Category:** Logstash\
**Created:** [November 17, 2020, 9:26am UTC](https://discuss.elastic.co/t/does-logstash-continue-getting-log-from-kafka-if-it-cannot-send-log-to-els/255648 "2020-11-17T09:26:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AkatsukiPain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akatsukipain/32/78358_2.png) [@AkatsukiPain](https://discuss.elastic.co/u/AkatsukiPain)\
**Post date:** [November 17, 2020, 9:26am UTC](https://discuss.elastic.co/t/does-logstash-continue-getting-log-from-kafka-if-it-cannot-send-log-to-els/255648/1 "2020-11-17T09:26:04Z")

</div>

I want to build a topology like this, but I don't know the behavior of logstash when elasticsearch dies ( Logstash cannot send the log to Elasticsearch). There are 2 situations that I'm thinking

> 1. Logstash will stop getting logs from Kafka.
> 2. Logstash keep getting logs from Kafka and save to its queue, if elasticsearch is online, logstash will send logs from the queue to ELS.

Please help me explain more about this.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d2b9481aefd453d3281ccc88e455bfc8c882642b.png)

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 17, 2020, 9:40am UTC](https://discuss.elastic.co/t/does-logstash-continue-getting-log-from-kafka-if-it-cannot-send-log-to-els/255648/2 "2020-11-17T09:40:43Z")

</div>

Hi,

LogStash will keep receiving events even if ElasticSearch is unavailable. There are 2 points though:

1. By default LogStash will keep the events in memory. If LogStash is restarted all pending events are lost. To solve this use a [persistent queue](https://www.elastic.co/guide/en/logstash/current/persistent-queues.html)
2. The storage space for pending messages is fixed. If the queue is full no new messages are received. The maximum size can be defined for persistent queues

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2020, 9:41am UTC](https://discuss.elastic.co/t/does-logstash-continue-getting-log-from-kafka-if-it-cannot-send-log-to-els/255648/3 "2020-12-15T09:41:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
