# How to handle replay of eventhub data

**URL:** <https://discuss.elastic.co/t/how-to-handle-replay-of-eventhub-data/347230>\
**Category:** Logstash\
**Created:** [November 15, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-to-handle-replay-of-eventhub-data/347230 "2023-11-15T14:02:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![favetelinguis](https://avatars.discourse-cdn.com/v4/letter/f/bc8723/32.png) [@favetelinguis](https://discuss.elastic.co/u/favetelinguis)\
**Post date:** [November 15, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-to-handle-replay-of-eventhub-data/347230/1 "2023-11-15T14:02:15Z")

</div>

I am currently running some disaster recovery tests on out logstash which uses the Azure Eventhub input plugin and elastic output. My test includes changing the URL to elastic so that sending will fail. However once I restore the url the eventhub plugin seems to have no idea that the elastic output has failed for some time. Now I would like to tell logstash to resend all messages on the eventhub which has not been sent. I have found the look-back option but that is only valid the first time logstash reads from eventhub so not much help for me. What would be the standard way to reply the last hour for example of messages on eventhub for logstash using my setup. Below is the eventhub input config:

```auto
      input {
        azure_event_hubs {
          event_hub_connections => ['${EVENT_HUB_CONNECTION}']
          threads => 2
          decorate_events => true
          consumer_group => "logstash-consumer-group"
          storage_connection => '${EVENT_HUB_STORAGE_CONNECTION}'
          storage_container => "logstashconsumersstate"
        }
      }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-to-handle-replay-of-eventhub-data/347230/2 "2023-12-13T14:02:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
