# Horizontally scaling Logstash - Per User Guide

**URL:** <https://discuss.elastic.co/t/horizontally-scaling-logstash-per-user-guide/39340>\
**Category:** Logstash\
**Created:** [January 15, 2016, 3:23pm UTC](https://discuss.elastic.co/t/horizontally-scaling-logstash-per-user-guide/39340 "2016-01-15T15:23:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jt1522](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jt1522](https://discuss.elastic.co/u/jt1522)\
**Post date:** [January 15, 2016, 3:23pm UTC](https://discuss.elastic.co/t/horizontally-scaling-logstash-per-user-guide/39340/1 "2016-01-15T15:23:11Z")

</div>

I have been working with the ELK stack for quite some time, but now that I am going to production I need to scale Logstash for larger throughput. I have seen the guide which shows the distributed layout:

[https://www.elastic.co/guide/en/logstash/current/deploying-and-scaling.html#deploying-logstash-ha](https://www.elastic.co/guide/en/logstash/current/deploying-and-scaling.html#deploying-logstash-ha)

However, I have never seen example configs/code that shows how this works. I need to listen on 514 for syslog but a single logstash instance cannot handle the volume my system is producing. Also note that the customer will not allow install of any collector on their servers (i.e. no Beats) ☹ We have to be able to listen on a single port as if we were a logging server.

If I set each of my logstash instances to listen of port 514, how do I prevent message duplication. The diagram in the guide suggests that you can send data to many instances and then into a queue.

Thanks guys.

-Jonathan

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 16, 2016, 1:16am UTC](https://discuss.elastic.co/t/horizontally-scaling-logstash-per-user-guide/39340/2 "2016-01-16T01:16:09Z")

</div>

You'd want a load balancer that listens on the port and feeds to multiple LS instances. Something like haproxy would work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:15am UTC](https://discuss.elastic.co/t/horizontally-scaling-logstash-per-user-guide/39340/3 "2017-07-06T05:15:32Z")

</div>


