# File beat to switch logstash host in case of failure

**URL:** <https://discuss.elastic.co/t/file-beat-to-switch-logstash-host-in-case-of-failure/72911>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 26, 2017, 2:53pm UTC](https://discuss.elastic.co/t/file-beat-to-switch-logstash-host-in-case-of-failure/72911 "2017-01-26T14:53:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Honda\_fred\_elk](https://avatars.discourse-cdn.com/v4/letter/h/919ad9/32.png) [@Honda\_fred\_elk](https://discuss.elastic.co/u/Honda_fred_elk)\
**Post date:** [January 26, 2017, 2:53pm UTC](https://discuss.elastic.co/t/file-beat-to-switch-logstash-host-in-case-of-failure/72911/1 "2017-01-26T14:53:08Z")

</div>

Hi,

I am using filebeat to export logs from client machine to logstash server..

My scenario is:

1. I have installed logstash (ELK server) in two servers. both the logstash will be listening always.
2. I need to export logs to always to Host 1.
3. If there is any issue (network or EKL Server down) in Host1... then filebeat has to export logs to Host 2.

I read that If I have more than one hosts configured in output.logstash.hosts[] in filebeat.yml.. then every single log will be sent to both the hosts.

But I dont want to send both the hosts always..  
It should be sent Host 1 always, In case of failure then filebeat should send logs to Host 2.

Is this scenario possible in filebeat configuration?

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 26, 2017, 9:38pm UTC](https://discuss.elastic.co/t/file-beat-to-switch-logstash-host-in-case-of-failure/72911/2 "2017-01-26T21:38:23Z")

</div>

If you are referring to [https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html#loadbalance](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html#loadbalance) then it doesn't send every event to all hosts, it "_balances published events onto all Logstash hosts_", which means it will send some to host 1, some to host 2, some to host N.

That means that if host 1 is down, it will switch to using the other hosts.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 27, 2017, 12:45am UTC](https://discuss.elastic.co/t/file-beat-to-switch-logstash-host-in-case-of-failure/72911/3 "2017-01-27T00:45:26Z")

</div>

if load balancing is disabled, but mutliple hosts are configured, one host is selected randomly (there is no precedence). If one host becomes unreachable, another one is selected randomly.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 27, 2017, 1:03am UTC](https://discuss.elastic.co/t/file-beat-to-switch-logstash-host-in-case-of-failure/72911/4 "2017-01-27T01:03:03Z")

</div>

I've raised this PR to clear this up [https://github.com/elastic/beats/pull/3476](https://github.com/elastic/beats/pull/3476)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2017, 1:03am UTC](https://discuss.elastic.co/t/file-beat-to-switch-logstash-host-in-case-of-failure/72911/5 "2017-02-24T01:03:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
