# How to implement failover with merely Syslog over UDP

**URL:** <https://discuss.elastic.co/t/how-to-implement-failover-with-merely-syslog-over-udp/138187>\
**Category:** Logstash\
**Created:** [July 2, 2018, 11:17am UTC](https://discuss.elastic.co/t/how-to-implement-failover-with-merely-syslog-over-udp/138187 "2018-07-02T11:17:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Post date:** [July 2, 2018, 11:17am UTC](https://discuss.elastic.co/t/how-to-implement-failover-with-merely-syslog-over-udp/138187/1 "2018-07-02T11:17:26Z")

</div>

Hi

We have the following setup:  
Syslog/UDP stream from all of our devices sent to two nginx-loadbalancers which forwards the UDP stream to two logstash nodes. This works great for load-balancing but not for failover. If one of the logstash machines for some reason goes offline, nginx will simply continue to send data to the offline node since its UDP.

I was wondering if the community has solved this in the past? And any general recommendations are welcome as well.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [July 2, 2018, 2:17pm UTC](https://discuss.elastic.co/t/how-to-implement-failover-with-merely-syslog-over-udp/138187/2 "2018-07-02T14:17:33Z")

</div>

You will need to look to a VRRP/Keepalived solution. This article discusses and example of this...

> **[UDP Load Balancing with Keepalived – 500px Engineering Blog](https://developers.500px.com/udp-load-balancing-with-keepalived-167382d7ad08?gi=7c57bc516a48)**
>
> About halfway into my four month internship as a platform developer at 500px, I was faced with the problem of load balancing UDP packets…

---

<div class="post-metadata">

**Author:** ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Post date:** [July 2, 2018, 3:02pm UTC](https://discuss.elastic.co/t/how-to-implement-failover-with-merely-syslog-over-udp/138187/3 "2018-07-02T15:02:55Z")

</div>

Thanks! However, won't that eliminate the load-balancing aspect? It looks as a good solution other than its eliminating the load-balancing since only one logstash machine can be master.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2018, 3:02pm UTC](https://discuss.elastic.co/t/how-to-implement-failover-with-merely-syslog-over-udp/138187/4 "2018-07-30T15:02:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
