# How to properly detect and handle transport errors in Elasticsearch logging (latest versions)

**URL:** <https://discuss.elastic.co/t/how-to-properly-detect-and-handle-transport-errors-in-elasticsearch-logging-latest-versions/382790>\
**Category:** Elasticsearch\
**Created:** [October 16, 2025, 1:47pm UTC](https://discuss.elastic.co/t/how-to-properly-detect-and-handle-transport-errors-in-elasticsearch-logging-latest-versions/382790 "2025-10-16T13:47:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guido\_hernan\_Gagliar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guido_hernan_gagliar/32/145395_2.png) [@Guido\_hernan\_Gagliar](https://discuss.elastic.co/u/Guido_hernan_Gagliar)\
**Post date:** [October 16, 2025, 1:47pm UTC](https://discuss.elastic.co/t/how-to-properly-detect-and-handle-transport-errors-in-elasticsearch-logging-latest-versions/382790/1 "2025-10-16T13:47:10Z")

</div>

Hi everyone! 👋

I'm new to Elasticsearch and still learning, so I’d really appreciate some guidance.

I’m trying to understand the **best way to detect and handle transport errors** when sending logs to Elasticsearch (using the latest versions). My current issue is that when my app sends logs to ELK and Elasticsearch is down, the write attempts cause my microservice to crash.

I’d like to implement a **detection or fallback mechanism** so that, if an error occurs during log transport, the logs are sent instead to the **OpenShift console** , where I already have **Filebeat** configured to enqueue them.

For context, I’m doing all of this from a **pivot microservice using Winston**.  
What would you recommend as the most reliable and modern approach to handle this scenario?

Thanks a lot for your help and patience as I learn!

---

<div class="post-metadata">

**Author:** ![Sophia\_Solomon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sophia_solomon/32/141226_2.png) [@Sophia\_Solomon](https://discuss.elastic.co/u/Sophia_Solomon)\
**Post date:** [October 20, 2025, 8:07am UTC](https://discuss.elastic.co/t/how-to-properly-detect-and-handle-transport-errors-in-elasticsearch-logging-latest-versions/382790/2 "2025-10-20T08:07:20Z")

</div>

Hi @Guido_hernan_Gagliar,  
How are you sending the logs to Elasticsearch using Winston? Are using the [ECS approach with Winston and Filebeat as documented here](https://www.elastic.co/docs/reference/ecs/logging/nodejs/winston)?  
If you could share the code that would be amazing. Also, you could send the logs to both OpenShift and Elasticsearch using either Logstash or an OTel collector for redundancy. Alternatively you can use the Red Hat OpenShift Logging Operator as discussed [here](https://www.elastic.co/observability-labs/blog/openshift-container-logs-red-hat-logging-operator).

---

<div class="post-metadata">

**Author:** ![Guido\_hernan\_Gagliar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guido_hernan_gagliar/32/145395_2.png) [@Guido\_hernan\_Gagliar](https://discuss.elastic.co/u/Guido_hernan_Gagliar)\
**Post date:** [October 20, 2025, 11:28am UTC](https://discuss.elastic.co/t/how-to-properly-detect-and-handle-transport-errors-in-elasticsearch-logging-latest-versions/382790/3 "2025-10-20T11:28:49Z")

</div>

```auto
import { createLogger, transports, config, LoggerOptions } from 'winston';
import { indexPrefix, indexSuffixPattern, esTransformer, client } from './esConfig';
import { ElasticsearchTransport, ElasticsearchTransportOptions } from 'winston-elasticsearch';
import { esFormat, httpConsoleFormat, debuggerFormat } from './formats';
import { environment } from './environment';

const inTesting = process.env.NODE_ENV === 'test';

const ElasticSearch: { [key: string]: ElasticsearchTransportOptions } = {
    logger: {
        level: 'info',
        client,
        indexPrefix: indexPrefix.logger,
        indexSuffixPattern,
        format: esFormat,
        transformer: esTransformer.logger,
        // ensureIndexTemplate: false,
        silent: environment.SILENT_ELK_LOGS,
    },
    debugger: {
        level: 'debug',
        client,
        indexPrefix: indexPrefix.debugger,
        indexSuffixPattern,
        format: esFormat,
        transformer: esTransformer.debugger,
        // ensureIndexTemplate: false,
        silent: environment.SILENT_ELK_LOGS_DEBUG,
    },
};
const Console: { [key: string]: LoggerOptions } = {
    logger: {
        level: 'info',
        format: httpConsoleFormat,
        silent: environment.SILENT_STDOUT_LOGS,
    },
    debugger: {
        level: 'debug',
        format: debuggerFormat,
        silent: environment.SILENT_STDOUT_LOGS_DEBUG,
    },
};

const loggerConsoleTransport = new transports.Console(Console.logger);
const debuggerTransport = new transports.Console(Console.debugger);
const loggerESTransport = new ElasticsearchTransport(ElasticSearch.logger);
const debuggerESTransport = new ElasticsearchTransport(ElasticSearch.debugger);

const loggerHttp = createLogger({
    exitOnError: false,
    handleExceptions: true,
    transports: [loggerESTransport, loggerConsoleTransport],
    levels: config.npm.levels,
    silent: inTesting,
});

const logger = createLogger({
    transports: [debuggerTransport, debuggerESTransport],
    levels: config.npm.levels,
    silent: inTesting,
});

loggerHttp.on('error', (error) => {
    // eslint-disable-next-line no-console
    console.error('loggerHttp error caught', error);
});
loggerESTransport.on('warning', (error: any) => {
    // eslint-disable-next-line no-console
    console.error('Elastic Search Transport Error caught', error);
});
debuggerESTransport.on('warning', (error: any) => {
    // eslint-disable-next-line no-console
    console.error('Elastic Search Transport Error caught', error);
});
export { loggerHttp, logger, loggerESTransport, debuggerESTransport };

```

Yes, this is the code I am currently using for transport. Obviously, I inherited all of this; it was implemented several years ago.  
I have now updated everything to the latest versions, and I will follow the documentation you recommended to perform transport with Winston.  
My idea is not to change the current operation, as there are many systems connected, and I don't want to disrupt the functioning of this entire environment.  
Thank you very much for your help.
