# IP based failover in Logstash

**URL:** <https://discuss.elastic.co/t/ip-based-failover-in-logstash/271978>\
**Category:** Logstash\
**Created:** [May 3, 2021, 12:34pm UTC](https://discuss.elastic.co/t/ip-based-failover-in-logstash/271978 "2021-05-03T12:34:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Debarati\_Goswami](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debarati_goswami/32/86043_2.png) [@Debarati\_Goswami](https://discuss.elastic.co/u/Debarati_Goswami)\
**Post date:** [May 3, 2021, 12:34pm UTC](https://discuss.elastic.co/t/ip-based-failover-in-logstash/271978/1 "2021-05-03T12:34:10Z")

</div>

Hi All ,

I have a requirement to collect logs from various sources into Logstash cluster (of 6 nodes) of which 4 nodes are for 4 different types of logs (rsyslog , IPFIX , SFTP and FluentD) and the last two nodes would work as dedicated backup nodes for Rsyslog and IPFIX in case of original node failure . My main problem here is that we are not provisioned with LoadBalancer , hence I am trying to find ways for IP based failover in Logstash to facilitate load movement from one node to another in case of Node failure.

I am absolutely new to ELK and any help would be extremely helpful for me.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 3, 2021, 3:02pm UTC](https://discuss.elastic.co/t/ip-based-failover-in-logstash/271978/2 "2021-05-03T15:02:32Z")

</div>

You can have two logstash instance listen on different IPs. How you would tell whatever is sending data to them to fail over from one to the other is a question about that software, not logstash.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 3, 2021, 4:44pm UTC](https://discuss.elastic.co/t/ip-based-failover-in-logstash/271978/3 "2021-05-03T16:44:33Z")

</div>

This is related to your infrastructure, logstash instances are independent from each other, so to implement a load balancing or failover mechanism you will need other tools.

In your case I recommend that you look at keepalived, you could create a VIP IP that would float between the two nodes according to some checks that you will need to implement, for example if the logstash service stops, keepalived would change the VIP IP to the other node.

But how to configure it is out of the scope of this forum.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [May 3, 2021, 5:49pm UTC](https://discuss.elastic.co/t/ip-based-failover-in-logstash/271978/4 "2021-05-03T17:49:29Z")

</div>

We have tested HA Proxy. basically your client will send data to x.x.x.x:port and that will be proxy ip:port

from there Proxy will send data to either node1:port and node2:port

if any of the node goes down all the data goes to one node and you have fail over.  
and when both logstash nodes are up they are load balanced.

on both logstash node you run same pipeline same config.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2021, 5:50pm UTC](https://discuss.elastic.co/t/ip-based-failover-in-logstash/271978/5 "2021-05-31T17:50:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
