# Get miss log from server

**URL:** <https://discuss.elastic.co/t/get-miss-log-from-server/39612>\
**Category:** Logstash\
**Created:** [January 20, 2016, 3:10am UTC](https://discuss.elastic.co/t/get-miss-log-from-server/39612 "2016-01-20T03:10:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [January 20, 2016, 3:10am UTC](https://discuss.elastic.co/t/get-miss-log-from-server/39612/1 "2016-01-20T03:10:18Z")

</div>

I'm using Logstash 2.1.1, ES 2.1.1, Filebeat 1.01, Winlogbeat 1.2.0 nightly build.

I'm deploy my system with model : Server (agent) -\> LS-forward -\> RabbitMQ-LS-Indexer-ES

I checked log in my server and have 70GB log/day. But i check Indices on ES, have 40GB log.  
And i check on RabbitMQ, don't have message queue.

So, why do miss log ?

Here is my config in LS-forwarder.

```
input {
  beats {
    port => 5044
  }
}
filter {
  mutate {
   add_field => {"beatname" => "%{[@metadata][beat]}"}
   add_field => {"beattype" => "%{[@metadata][type]}"}
  }
}
output {    
    rabbitmq {
        exchange => "logstash"
        exchange_type => "direct"
        key => "logstash-key"
        host => "10.1.6.244"
        vhost => "ELK"
        workers => 12
        durable => true
        persistent => true
        port => 5677
        user => "logstash"
        password => "***"

    }
}

```

In filebeat and winlogbeat. I set loadbalance with two LS-forwarder, workers = 4

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:15am UTC](https://discuss.elastic.co/t/get-miss-log-from-server/39612/2 "2017-07-06T05:15:07Z")

</div>


