# How to prevent logs missing

**URL:** <https://discuss.elastic.co/t/how-to-prevent-logs-missing/117157>\
**Category:** Elasticsearch\
**Created:** [January 26, 2018, 6:52am UTC](https://discuss.elastic.co/t/how-to-prevent-logs-missing/117157 "2018-01-26T06:52:14Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cwt](https://avatars.discourse-cdn.com/v4/letter/c/e47774/32.png) [@cwt](https://discuss.elastic.co/u/cwt)\
**Post date:** [January 26, 2018, 6:52am UTC](https://discuss.elastic.co/t/how-to-prevent-logs-missing/117157/1 "2018-01-26T06:52:14Z")

</div>

Hi folks,  
Please share your experience and tips, how to protect from losing logs, when the Logstash or Elastic falls.

RabbitMQ? Redis?

I have one standalone ELK stack.

Thank you

---

<div class="post-metadata">

**Author:** ![pixiuPL](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pixiupl/32/26299_2.png) [@pixiuPL](https://discuss.elastic.co/u/pixiuPL)\
**Post date:** [January 31, 2018, 12:16pm UTC](https://discuss.elastic.co/t/how-to-prevent-logs-missing/117157/2 "2018-01-31T12:16:16Z")

</div>

Rather clasterize and apply adequate cluster policy.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 31, 2018, 4:53pm UTC](https://discuss.elastic.co/t/how-to-prevent-logs-missing/117157/3 "2018-01-31T16:53:39Z")

</div>

But then, what if RabbitMQ fails?

Logstash has now persistent queues which would probably avoid some of the problems.

What exactly the problem you have or you are thinking that you can have?

---

<div class="post-metadata">

**Author:** ![cwt](https://avatars.discourse-cdn.com/v4/letter/c/e47774/32.png) [@cwt](https://discuss.elastic.co/u/cwt)\
**Post date:** [February 16, 2018, 11:37am UTC](https://discuss.elastic.co/t/how-to-prevent-logs-missing/117157/4 "2018-02-16T11:37:02Z")

</div>

ELK need to update more often than rabbitmq ))) I just want to protect from losing my logs when updating EL.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 16, 2018, 3:44pm UTC](https://discuss.elastic.co/t/how-to-prevent-logs-missing/117157/5 "2018-02-16T15:44:02Z")

</div>

I see.

Kafka is also a good candidate IMHO. RabbitMQ and Redis are nice as well.

---

<div class="post-metadata">

**Author:** ![pixiuPL](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pixiupl/32/26299_2.png) [@pixiuPL](https://discuss.elastic.co/u/pixiuPL)\
**Post date:** [February 27, 2018, 9:59am UTC](https://discuss.elastic.co/t/how-to-prevent-logs-missing/117157/6 "2018-02-27T09:59:42Z")

</div>

Redis is shit. Dont recommend it (esp for newbies)  
If Rabbit (or any other CaaS) fails, just restart it (either manually or by script) and you're back on track.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 27, 2018, 5:18pm UTC](https://discuss.elastic.co/t/how-to-prevent-logs-missing/117157/7 "2018-02-27T17:18:37Z")

</div>

These forums are not the place for that sort of language, so please refrain from using it in future.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2018, 5:18pm UTC](https://discuss.elastic.co/t/how-to-prevent-logs-missing/117157/8 "2018-03-27T17:18:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
