# Filebeat - Spooling to disk

**URL:** https://discuss.elastic.co/t/filebeat-spooling-to-disk/232800
**Category:** Beats
**Tags:** filebeat
**Created:** [May 15, 2020, 11:07am UTC](https://discuss.elastic.co/t/filebeat-spooling-to-disk/232800 "2020-05-15T11:07:55Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![saket\_gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saket_gupta/32/53099_2.png) [@saket\_gupta](https://discuss.elastic.co/u/saket_gupta)
#### Post date: [May 15, 2020, 11:07am UTC](https://discuss.elastic.co/t/filebeat-spooling-to-disk/232800/1 "2020-05-15T11:07:56Z")

</div>

Hi Team,

What happens when a filebeat's output like ELastic Search or Logstash is not avalable , however the log files are still written. Will it start consuming memory or will it default to disk.

I see that we can configure Disk Queue ([https://www.elastic.co/blog/brewing-in-beats-spooling-to-disk-in-Beats](https://www.elastic.co/blog/brewing-in-beats-spooling-to-disk-in-Beats)), however if I dont configure the disk Queue, will it still save events to the disk by default ?

My Filebeat version is 7.0.0

Thanks  
Saket

---

<div class="post-metadata">

### Author: ![saket\_gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saket_gupta/32/53099_2.png) [@saket\_gupta](https://discuss.elastic.co/u/saket_gupta)
#### Post date: [May 21, 2020, 12:25pm UTC](https://discuss.elastic.co/t/filebeat-spooling-to-disk/232800/2 "2020-05-21T12:25:55Z")

</div>

Request you to please help me with this.

Thanks  
Saket

---

<div class="post-metadata">

### Author: ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)
#### Post date: [May 21, 2020, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-spooling-to-disk/232800/3 "2020-05-21T13:25:50Z")

</div>

It keeps them in memory. See: [https://www.elastic.co/guide/en/beats/filebeat/master/configuring-internal-queue.html](https://www.elastic.co/guide/en/beats/filebeat/master/configuring-internal-queue.html)

---

<div class="post-metadata">

### Author: ![saket\_gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saket_gupta/32/53099_2.png) [@saket\_gupta](https://discuss.elastic.co/u/saket_gupta)
#### Post date: [May 21, 2020, 2:29pm UTC](https://discuss.elastic.co/t/filebeat-spooling-to-disk/232800/4 "2020-05-21T14:29:28Z")

</div>

Thanks for your reply.

When I shutdown logstash which is input to my filebeat, and add some logs to be parsed by filebeat, I see that the memory consumption is raised but only for some short duration. Does it release memory and sends them automatically once the logstash is up and running again? If yes, then does registry file helps in this ?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 18, 2020, 2:37pm UTC](https://discuss.elastic.co/t/filebeat-spooling-to-disk/232800/5 "2020-06-18T14:37:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
