# Filebeat-failover

**URL:** https://discuss.elastic.co/t/filebeat-failover/134685
**Category:** Beats
**Tags:** filebeat
**Created:** [June 5, 2018, 7:40pm UTC](https://discuss.elastic.co/t/filebeat-failover/134685 "2018-06-05T19:40:54Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![surendrakotte](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@surendrakotte](https://discuss.elastic.co/u/surendrakotte)
#### Post date: [June 5, 2018, 7:40pm UTC](https://discuss.elastic.co/t/filebeat-failover/134685/1 "2018-06-05T19:40:54Z")

</div>

Hello,

Do we have a way to configure failover for filebeat process?

Thanks in advance!

Surendra

---

<div class="post-metadata">

### Author: ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)
#### Post date: [June 5, 2018, 7:44pm UTC](https://discuss.elastic.co/t/filebeat-failover/134685/2 "2018-06-05T19:44:48Z")

</div>

Hi @surendrakotte,

What do you mean by a failover for filebeat process?

---

<div class="post-metadata">

### Author: ![surendrakotte](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@surendrakotte](https://discuss.elastic.co/u/surendrakotte)
#### Post date: [June 5, 2018, 8:48pm UTC](https://discuss.elastic.co/t/filebeat-failover/134685/3 "2018-06-05T20:48:23Z")

</div>

Yes, like a secondary process to take over the processing incase primary fails.

---

<div class="post-metadata">

### Author: ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)
#### Post date: [June 6, 2018, 10:12am UTC](https://discuss.elastic.co/t/filebeat-failover/134685/4 "2018-06-06T10:12:51Z")

</div>

Filebeat is deployed in all nodes, and in each one of them it keeps a registry with the logs read and succesfully sent, so no data should be lost if the process is restarted. In principle it shouldn't "fail" or stop unexpectedly (if it does it should be considered a bug, so please report it 🙂). If you are using a service manager (like systemd in Linux) to start filebeat you can configure it to restart the process automatically if it stops unexpectedly.

You can also configure multiple hosts in the output, so if one fail another one can be used.

Filebeat 6.3 will have a [new spooling feature](https://github.com/elastic/beats/pull/6581) (in beta) that will store events locally on disk if all the hosts in the output are down, so they can be sent when the hosts are back online.

I hope it helps to answer your question, if you have a more specific question or about an specific scenario please ask 🙂

---

<div class="post-metadata">

### Author: ![surendrakotte](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@surendrakotte](https://discuss.elastic.co/u/surendrakotte)
#### Post date: [June 6, 2018, 1:16pm UTC](https://discuss.elastic.co/t/filebeat-failover/134685/5 "2018-06-06T13:16:29Z")

</div>

Hi Jaime,

Thanks for explaining it to me! Can you let me know when 6.3 is generally available?

---

<div class="post-metadata">

### Author: ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)
#### Post date: [June 6, 2018, 4:45pm UTC](https://discuss.elastic.co/t/filebeat-failover/134685/6 "2018-06-06T16:45:48Z")

</div>

I cannot confirm a specific date, but we expect to release 6.3 really soon.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 4, 2018, 4:45pm UTC](https://discuss.elastic.co/t/filebeat-failover/134685/7 "2018-07-04T16:45:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
