# How to monitor logstash itself?

**URL:** https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172
**Category:** Logstash
**Created:** [August 11, 2015, 5:23am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172 "2015-08-11T05:23:40Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![MichaelScofield](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaelscofield/32/4118_2.png) [@MichaelScofield](https://discuss.elastic.co/u/MichaelScofield)
#### Post date: [August 11, 2015, 5:23am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/1 "2015-08-11T05:23:40Z")

</div>

Are there any tools that can monitor logstash's health? I googled it but found no answers.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 11, 2015, 5:27am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/2 "2015-08-11T05:27:24Z")

</div>

The following discussion from a day or two ago might be helpful. If not, please be more specific in what you're after.

> [@How to get alerts for logstash failures of plugins / input / filters?](https://discuss.elastic.co/t/how-to-get-alerts-for-logstash-failures-of-plugins-input-filters/27087):
>
> Inside logstash, what is the official mechanism to know about any critical errors that happen with plugins / inputs / filters during the production run? For example, I am using http\_poller input and elastic output. Say, if for some reason the http\_poller is unable to read the input properly from the url or elastic unable to save the output - is there anyway I can configure logstash to send me alert mails ? Generating debug / stdout errors to console would not help in backend systems case - rig…

---

<div class="post-metadata">

### Author: ![MichaelScofield](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaelscofield/32/4118_2.png) [@MichaelScofield](https://discuss.elastic.co/u/MichaelScofield)
#### Post date: [August 11, 2015, 5:47am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/3 "2015-08-11T05:47:13Z")

</div>

Thanks! That discussion is enlightening. However, I am looking for some metrics like "how many events are received/sent per second" or "how many bytes are received/sent per second".

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 11, 2015, 5:55am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/4 "2015-08-11T05:55:37Z")

</div>

Well, if you run statsd you can have Logstash ping it for each message and you'll at least get events/s.

---

<div class="post-metadata">

### Author: ![MichaelScofield](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaelscofield/32/4118_2.png) [@MichaelScofield](https://discuss.elastic.co/u/MichaelScofield)
#### Post date: [August 11, 2015, 6:27am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/5 "2015-08-11T06:27:14Z")

</div>

Thanks for the reply, but I'm not very clear about how to "ping" the statsd.

Do you mean that I have to include the statsd output plugin and have it feed with some event field like timestamp?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 11, 2015, 6:32am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/6 "2015-08-11T06:32:25Z")

</div>

> Do you mean that I have to include the statsd output plugin and have it feed with some event field like timestamp?

Not the timestamp since that's implied but you could send metrics to a counter-type metric named logstash.events or whatever you want, and stastd will periodically emit both the absolute count and the rate.

---

<div class="post-metadata">

### Author: ![MichaelScofield](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaelscofield/32/4118_2.png) [@MichaelScofield](https://discuss.elastic.co/u/MichaelScofield)
#### Post date: [August 11, 2015, 6:36am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/7 "2015-08-11T06:36:23Z")

</div>

Ah, thanks! 🙂

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [August 11, 2015, 10:21am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/8 "2015-08-11T10:21:31Z")

</div>

LS 2.0 will have this sort of thing exposed 🙂

---

<div class="post-metadata">

### Author: ![MichaelScofield](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaelscofield/32/4118_2.png) [@MichaelScofield](https://discuss.elastic.co/u/MichaelScofield)
#### Post date: [August 11, 2015, 10:25am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/9 "2015-08-11T10:25:18Z")

</div>

Thx! Really looking forward to 2.0, it's better to have these kinds of metrics got from logstash itself.

Is there any plan releasing 2.0?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [August 11, 2015, 10:35am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/10 "2015-08-11T10:35:24Z")

</div>

I'm not sure of the timeline on that one sorry.

---

<div class="post-metadata">

### Author: ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)
#### Post date: [August 13, 2015, 4:41pm UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/11 "2015-08-13T16:41:58Z")

</div>

@MichaelScofield we're still working on figuring out the timeline at the moment. There will def be an announcement when we have one however!

---

<div class="post-metadata">

### Author: ![m1k3ga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/m1k3ga/32/4173_2.png) [@m1k3ga](https://discuss.elastic.co/u/m1k3ga)
#### Post date: [August 14, 2015, 7:44am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/12 "2015-08-14T07:44:45Z")

</div>

According to the statsd doc it uses the %{host} field as logging host.  
In our setup with many logstash shippers and indexers the host is always the name of the original host where the logfile was read from.  
**How** do you distinguish between each instance for monitoring each logstash instance?

We use the metrics plugin with environment plugin ($HOSTNAME) to trigger a heartbeat event from each logstash instance every 60 seconds.

But statsd seems to be interesting, i will have a look at it.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:31am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172/13 "2017-07-06T05:31:59Z")

</div>


