# Events are lost when elasticsearch output is temporary unavailable

**URL:** <https://discuss.elastic.co/t/events-are-lost-when-elasticsearch-output-is-temporary-unavailable/272176>\
**Category:** Logstash\
**Created:** [May 5, 2021, 11:20am UTC](https://discuss.elastic.co/t/events-are-lost-when-elasticsearch-output-is-temporary-unavailable/272176 "2021-05-05T11:20:37Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [May 6, 2021, 8:23am UTC](https://discuss.elastic.co/t/events-are-lost-when-elasticsearch-output-is-temporary-unavailable/272176/4 "2021-05-06T08:23:44Z")

</div>

Hi,

Good to know that the suggestions work.

I think that the storage overhead in LogStash is to be expected:

1. Elasticsearch compresses data by default (see details [here](https://www.elastic.co/blog/save-space-and-money-with-improved-storage-efficiency-in-elasticsearch-7-10)) while LogStash does not store the queue compressed (I think)
2. LogStash stores metadata from each input/output/filter in each event. This contains for example the source ip for beats input. You can view the metadata for example by writting all events including metadata to a file (see details here: [How to access the value in the logstash metadata - #2 by Christian\_Dahlqvist](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200/2)).

Best regards  
Wolfram

---

_[View the full topic](https://discuss.elastic.co/t/events-are-lost-when-elasticsearch-output-is-temporary-unavailable/272176)._
