# Enable filebeat caching during unavailablity

**URL:** <https://discuss.elastic.co/t/enable-filebeat-caching-during-unavailablity/308608>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 30, 2022, 6:27pm UTC](https://discuss.elastic.co/t/enable-filebeat-caching-during-unavailablity/308608 "2022-06-30T18:27:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [June 30, 2022, 6:27pm UTC](https://discuss.elastic.co/t/enable-filebeat-caching-during-unavailablity/308608/1 "2022-06-30T18:27:16Z")

</div>

Hello,

I hope you and your loved ones are safe and healthy.

I am running a cluster that collects logs from sources on the internet. I need to enable caching of logs in case the next hop is not reachable as dropping logs is detrimental to my project.  
Following is my architecture:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3d0353d9de34407b32622624c42af39b828a48b.png)

Various log sources (mostly running Linux) send logs using **Filebeat** to my homelab which are collected by **Logstash**.

A. This is where the **first unavailability** can occur. As I use home ISP and do not commercial agreement, there are availability issues. How do I enable caching of logs (up to 48 hours) at filebeat in case the next hop (logstash hosted in my homelab) is not available.

_I have enabled deduplication in filebeat + logstash using: [Deduplicate data | Filebeat Reference [8.3] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-deduplication.html)_

---

<div class="post-metadata">

**Author:** ![ulisses](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ulisses/32/107375_2.png) [@ulisses](https://discuss.elastic.co/u/ulisses)\
**Post date:** [June 30, 2022, 6:29pm UTC](https://discuss.elastic.co/t/enable-filebeat-caching-during-unavailablity/308608/2 "2022-06-30T18:29:46Z")

</div>

Maybe this?

[Internal Queue](https://www.elastic.co/guide/en/beats/filebeat/8.2/configuring-internal-queue.html)

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [July 16, 2022, 12:58pm UTC](https://discuss.elastic.co/t/enable-filebeat-caching-during-unavailablity/308608/3 "2022-07-16T12:58:17Z")

</div>

Thank you for this.

I initially thought the default enabled setting of 10G would take care. However, I see that it needs to be specified. I will add this and let the community know once I simulate an outage. Thank you very much. 🙂

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [July 23, 2022, 3:48am UTC](https://discuss.elastic.co/t/enable-filebeat-caching-during-unavailablity/308608/4 "2022-07-23T03:48:02Z")

</div>

@ulisses , thank you very much. I simulated a downtime yesterday for 6 hours and there were no log loss. I will simulate a longer one today to validate the settings. I've marked it as a solution.

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [July 23, 2022, 5:15pm UTC](https://discuss.elastic.co/t/enable-filebeat-caching-during-unavailablity/308608/5 "2022-07-23T17:15:39Z")

</div>

@ulisses - It works. Thank you very much! Amazing 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2022, 7:16pm UTC](https://discuss.elastic.co/t/enable-filebeat-caching-during-unavailablity/308608/6 "2022-08-20T19:16:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
