# Gelf Input plugin dropping messages

**URL:** <https://discuss.elastic.co/t/gelf-input-plugin-dropping-messages/325260>\
**Category:** Logstash\
**Created:** [February 10, 2023, 12:08pm UTC](https://discuss.elastic.co/t/gelf-input-plugin-dropping-messages/325260 "2023-02-10T12:08:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![karlo95](https://avatars.discourse-cdn.com/v4/letter/k/ba8739/32.png) [@karlo95](https://discuss.elastic.co/u/karlo95)\
**Post date:** [February 10, 2023, 12:08pm UTC](https://discuss.elastic.co/t/gelf-input-plugin-dropping-messages/325260/1 "2023-02-10T12:08:36Z")

</div>

Hello,  
I'm having problems with Gelf Input plugin dropping messages when listening on UDP.  
When a lot of messagess comes in same time, it seems like logstash plugin is dropping them randomly.  
E.g. when I restart quarkus pod it only logs out few lines of code, while directly in pod logs I can see all log messages.

Pod logs:

```auto
2023-02-10 11:50:28,629 [1] INFO [liq.database] (main) Set default schema name to dbo
2023-02-10 11:50:29,111 [1] INFO [liq.changelog] (main) Reading from DATABASECHANGELOG
2023-02-10 11:50:29,301 [1] INFO [liq.lockservice] (main) Successfully acquired change log lock
2023-02-10 11:50:29,878 [1] INFO [liq.lockservice] (main) Successfully released change log lock
2023-02-10 11:50:30,262 [1] INFO [io.sma.rea.mes.amqp] (main) SRMSG16212: Establishing connection with AMQP broker
2023-02-10 11:50:30,390 [1] INFO [io.quarkus] (main) quarkus on JVM (powered by Quarkus 2.9.1.Final) started in 3.644s. Listening on: http://0.0.0.0:8080
2023-02-10 11:50:30,392 [1] INFO [io.quarkus] (main) Profile prod activated. 
2023-02-10 11:50:30,392 [1] INFO [io.quarkus] (main) Installed features: [agroal, cdi, hibernate-orm, hibernate-orm-panache, jdbc-mssql, liquibase, logging-gelf, narayana-jta, rest-client, rest-client-jackson, resteasy-reactive, resteasy-reactive-jackson, scheduler, smallrye-context-propagation, smallrye-health, smallrye-openapi, smallrye-reactive-messaging, smallrye-reactive-messaging-amqp, swagger-ui, vertx]
2023-02-10 11:50:30,539 [1] INFO [io.sma.rea.mes.amqp] (vert.x-eventloop-thread-0) SRMSG16213: Connection with AMQP broker established

```

Logs written by logstash:

```auto
2023-02-10 11:50:29,301 [1] INFO [liq.lockservice] (main) Successfully acquired change log lock

```

My logstash configuration is:

```auto
input {
        gelf {
        port => 12201
        type => "gelf_input"
      }
}

output {
        if [type] == "gelf_input" {
          elasticsearch {
                hosts => ["xxx"]
                user => "username"
                password => "password"
          }
        }
}

```

When switching to TCP everything works ok, but I would like to avoid using TCP.  
What I found related to this problems is this: [logstash is not processing most of the gelf messages · Issue #3471 · elastic/logstash · GitHub](https://github.com/elastic/logstash/issues/3471)  
Is there any workaround?  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2023, 12:09pm UTC](https://discuss.elastic.co/t/gelf-input-plugin-dropping-messages/325260/2 "2023-03-10T12:09:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
