# How to make Logstash highly available

**URL:** <https://discuss.elastic.co/t/how-to-make-logstash-highly-available/29926>\
**Category:** Logstash\
**Created:** [September 24, 2015, 3:54pm UTC](https://discuss.elastic.co/t/how-to-make-logstash-highly-available/29926 "2015-09-24T15:54:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [September 24, 2015, 3:54pm UTC](https://discuss.elastic.co/t/how-to-make-logstash-highly-available/29926/1 "2015-09-24T15:54:40Z")

</div>

Hi Experts,

My plan is to make LS highly available as I did it for ES and Kibana.  
So I have load balancer for ES and for Kibana. Not sure how I achieve this for LS. Please suggest.

Thanks  
VG

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 24, 2015, 5:10pm UTC](https://discuss.elastic.co/t/how-to-make-logstash-highly-available/29926/2 "2015-09-24T17:10:23Z")

</div>

Since Logstash does not serve user requests in the same way as ES and Kibana it's not clear what "high availability" means.

What kind of inputs and filters do you have? If you have natural buffering of incoming messages because they come from files on a file system and you ship messages via TCP it's typically fine if Logstash is unavailable for short periods of time. The log shipper will pause until Logstash is available again and resend what has been queued up. This strategy obviously won't work for UDP datagrams sent directly from log clients.

With TCP connections you can of course put Logstash behind a load balancer, much like you've apparently done with ES and Kibana.

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [September 24, 2015, 5:12pm UTC](https://discuss.elastic.co/t/how-to-make-logstash-highly-available/29926/3 "2015-09-24T17:12:19Z")

</div>

Thanks for the response Magnus,

Actually I have UDP port in picture , so any solution in UDP case ?

---

<div class="post-metadata">

**Author:** ![PhaedrusTheGreek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phaedrusthegreek/32/4884_2.png) [@PhaedrusTheGreek](https://discuss.elastic.co/u/PhaedrusTheGreek)\
**Post date:** [September 24, 2015, 6:15pm UTC](https://discuss.elastic.co/t/how-to-make-logstash-highly-available/29926/4 "2015-09-24T18:15:06Z")

</div>

@vikas_gopal @magnusbaeck

Check out this discussion as well:

> [@Question on "Multiple Connections for Logstash High Availability" diagram published in logstash documentation](https://discuss.elastic.co/t/question-on-multiple-connections-for-logstash-high-availability-diagram-published-in-logstash-documentation/29800/6):
>
> @RajkumarV There are a few ways that you can design this, but generally you want to have an intermediary device such as a load balancer to distribute traffic across your logstash instances. You could use any commercial hardware load balancer, or something like HAProxy. Send your UDP traffic to the Virtual IP on the Load balancer, which then distributes traffic evenly between logstash instances. Logstash does not have any awareness of the load balancing, it just simply listens for UDP messag…

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 24, 2015, 6:20pm UTC](https://discuss.elastic.co/t/how-to-make-logstash-highly-available/29926/5 "2015-09-24T18:20:59Z")

</div>

> Actually I have UDP port in picture , so any solution in UDP case ?

If you have a load balancer that supports UDP proxying then you should be good. Otherwise you can use DNS; a service would have to probe each Logstash instance and take it out of the rotation if it goes down. Perhaps Consul or etcd would be useful here. Otherwise there are certainly commercial options like F5 GTM.

---

<div class="post-metadata">

**Author:** ![Joshua\_Rich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_rich/32/44953_2.png) [@Joshua\_Rich](https://discuss.elastic.co/u/Joshua_Rich)\
**Post date:** [September 25, 2015, 12:14am UTC](https://discuss.elastic.co/t/how-to-make-logstash-highly-available/29926/6 "2015-09-25T00:14:57Z")

</div>

You should also have a read through the [Deploying and Scaling Logstash](https://www.elastic.co/guide/en/logstash/current/deploying-and-scaling.html) chapter of the documentation which explains some possible scenarios for scaling out for high availability and load balancing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:55am UTC](https://discuss.elastic.co/t/how-to-make-logstash-highly-available/29926/8 "2017-07-06T04:55:08Z")

</div>


