# ELK + redis query

**URL:** <https://discuss.elastic.co/t/elk-redis-query/28870>\
**Category:** Logstash\
**Created:** [September 8, 2015, 9:13pm UTC](https://discuss.elastic.co/t/elk-redis-query/28870 "2015-09-08T21:13:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![knightsg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/knightsg/32/4648_2.png) [@knightsg](https://discuss.elastic.co/u/knightsg)\
**Post date:** [September 8, 2015, 9:13pm UTC](https://discuss.elastic.co/t/elk-redis-query/28870/1 "2015-09-08T21:13:08Z")

</div>

Hi all,

I've set up ELK on AWS in a fault-tolerant configuration (multi-AZ), and  
have been looking at integrating redis into the stack to ease the load on  
logstash, as is commonly recommended. However, it seems to me that this  
just introduces a single point of failure into an otherwise redundant  
setup. While I gather that redis can be clustered, I have yet to find any  
documentation or how-tos that focus on using clustered redis as part of a  
fault-tolerant ELK setup.

I have my logstash instances load balanced and could theoretically scale  
out that tier if those instances were to become overloaded. Would anyone  
recommend this as a suitable alternative to having a single redis node?

Thanks,  
Guy

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 10, 2015, 8:32am UTC](https://discuss.elastic.co/t/elk-redis-query/28870/2 "2015-09-10T08:32:35Z")

</div>

It's an option, yes. But you'd have to figure out how an instance is overloaded.

---

<div class="post-metadata">

**Author:** ![knightsg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/knightsg/32/4648_2.png) [@knightsg](https://discuss.elastic.co/u/knightsg)\
**Post date:** [September 10, 2015, 9:50pm UTC](https://discuss.elastic.co/t/elk-redis-query/28870/3 "2015-09-10T21:50:52Z")

</div>

Thanks for that info Mark. Following on from my question, are you aware of any examples of creating a high availability redis setup for ELK?

---

<div class="post-metadata">

**Author:** ![knightsg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/knightsg/32/4648_2.png) [@knightsg](https://discuss.elastic.co/u/knightsg)\
**Post date:** [September 10, 2015, 9:55pm UTC](https://discuss.elastic.co/t/elk-redis-query/28870/4 "2015-09-10T21:55:51Z")

</div>

Actually, never mind that question. I did some further research and I realised the solution myself. Thanks again for your input.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 10, 2015, 10:31pm UTC](https://discuss.elastic.co/t/elk-redis-query/28870/5 "2015-09-10T22:31:50Z")

</div>

Care to share so others can learn?

---

<div class="post-metadata">

**Author:** ![knightsg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/knightsg/32/4648_2.png) [@knightsg](https://discuss.elastic.co/u/knightsg)\
**Post date:** [September 14, 2015, 5:36pm UTC](https://discuss.elastic.co/t/elk-redis-query/28870/6 "2015-09-14T17:36:04Z")

</div>

Sure. I realised I can just configure all the redis servers as individual inputs in my logstash config. This google group post discusses it in more detail: [https://groups.google.com/forum/#!topic/logstash-users/8Km9VFqapig](https://groups.google.com/forum/#!topic/logstash-users/8Km9VFqapig).

Another option is to put a redis instance on each logstash server, that way you just point logstash at 127.0.0.1:6379. However, if any logstash server completely dies then you'll also lose the events in the redis queue on that server, so this option would probably be my second choice.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:29am UTC](https://discuss.elastic.co/t/elk-redis-query/28870/7 "2017-07-06T05:29:12Z")

</div>


