# How does logstash route the data to a NEW primary ES node, not the old one?

**URL:** <https://discuss.elastic.co/t/how-does-logstash-route-the-data-to-a-new-primary-es-node-not-the-old-one/141030>\
**Category:** Logstash\
**Created:** [July 22, 2018, 12:18pm UTC](https://discuss.elastic.co/t/how-does-logstash-route-the-data-to-a-new-primary-es-node-not-the-old-one/141030 "2018-07-22T12:18:30Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 22, 2018, 3:17pm UTC](https://discuss.elastic.co/t/how-does-logstash-route-the-data-to-a-new-primary-es-node-not-the-old-one/141030/4 "2018-07-22T15:17:46Z")

</div>

> Ok, but either way - is writing data to both the replica and primary the way to go here - in order to be fault tolerant?

Again, saying "writing to both" is a misnomer since that's not what happens. But yes, list all known ES nodes in the elasticsearch output (and consider enabling the `sniffing` option) so that Logstash sends requests to any available node and lets the ES cluster figure out which node has the primary shard for each document that's to be stored. (For clusters sufficiently big to have master-only nodes it's a good idea to avoid those nodes.)

---

_[View the full topic](https://discuss.elastic.co/t/how-does-logstash-route-the-data-to-a-new-primary-es-node-not-the-old-one/141030)._
