# Last\_failure\_timestamp

**URL:** <https://discuss.elastic.co/t/last-failure-timestamp/305591>\
**Category:** Logstash\
**Created:** [May 25, 2022, 10:24am UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591 "2022-05-25T10:24:41Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [May 25, 2022, 10:24am UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/1 "2022-05-25T10:24:41Z")

</div>

Hi  
How I can manage reload parameter, and why this output is "null" failure\_timestamp" : null  
In my config I'm using

> log.level: info

```auto

        "outputs" : [ {
          "id" : "1937dea243c36a25e890be2892a0097740ae9274eeb655e6e243e823a211c8a9",
          "name" : "elasticsearch",
          "events" : {
            "in" : 292516,
            "duration_in_millis" : 174113,
            "out" : 292516
          },
          "documents" : {
            "successes" : 292516
          },
          "bulk_requests" : {
            "successes" : 141,
            "responses" : {
              "200" : 1
            },
            "failures" : 5
          }
        } ]
      },
      "reloads" : {
        "last_failure_timestamp" : null,
        "successes" : 0,
        "last_error" : null,
        "last_success_timestamp" : null,
        "failures" : 0

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 25, 2022, 11:52am UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/2 "2022-05-25T11:52:44Z")

</div>

Can you explain what you mean by _manage reload parameter_ ?

Logstash can auto-reload the configurations when a config file or the `pipelines.yml` change, but you need to set it in `logstash.yml`.

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [May 25, 2022, 11:58am UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/3 "2022-05-25T11:58:15Z")

</div>

I've meant after what time and how many times it can do a reload

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 25, 2022, 12:07pm UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/4 "2022-05-25T12:07:14Z")

</div>

If Logstash is configured to do auto reloads, it will reload **every** time a config file or the `pipelines.yml` is changed.

White auto-reload enabled Logstash check the config files and `pipelines.yml` for changes and if anything is changed, it will trigger a reload.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 26, 2022, 2:11am UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/5 "2022-05-26T02:11:43Z")

</div>

```auto
config.reload.automatic: true
config.reload.interval: 3s # default, usually 10-15 sec is fine

```

last\_failure\_timestamp - no failures=\>null, normal value when everything is working.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 26, 2022, 3:24am UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/6 "2022-05-26T03:24:44Z")

</div>

> [@leandrojmp](#):
>
> If Logstash is configured to do auto reloads, it will reload **every** time a config file or the `pipelines.yml` is changed.

Not sure that is true. Most timers in logstash trigger every 5 seconds, so two changes within 9.99 seconds may only trigger one reload. I may be wrong, but that what would be my starting assumption if I was going to test it (which I am not).

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [May 26, 2022, 7:51am UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/7 "2022-05-26T07:51:30Z")

</div>

But how many times(attempts) logstash will shoot to Elasticsearch ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 26, 2022, 12:08pm UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/8 "2022-05-26T12:08:33Z")

</div>

You are right @Badger , the auto-reload interval is configurable, so I think that multiple changes between that interval will probably trigger just one reload if the end file is different from the one that logstash was running.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 26, 2022, 12:10pm UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/9 "2022-05-26T12:10:10Z")

</div>

> [@INS](#):
>
> But how many times(attempts) logstash will shoot to Elasticsearch ?

It is not clear what you mean with that.

Logstash will reload the configuration and resume sending data to elasticsearch, if there is something wrong with the configuration it will fail to load the new configuration until it is fixed.

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [May 27, 2022, 7:06am UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/10 "2022-05-27T07:06:08Z")

</div>

we should talk about how many attempts with data logstash will try send to elastic under connection issue case

will it keep trying to send bulk of data or will there be a limit somewhere?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 27, 2022, 12:15pm UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/11 "2022-05-27T12:15:19Z")

</div>

> [@INS](#):
>
> we should talk about how many attempts with data logstash will try send to elastic under connection issue case

This has no relation with your original question, the `last_failure_timestamp` is related to a failure when trying to reload the pipeline nor when trying to send data to elasticsearch.

> [@INS](#):
>
> will it keep trying to send bulk of data or will there be a limit somewhere?

This is explained in the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#_retry_policy).

> HTTP requests to the bulk API are expected to return a 200 response code. All other response codes are **retried indefinitely**.

And about errors.

> The following document errors are handled as follows:
> 
> - 400 and 404 errors are sent to the dead letter queue (DLQ), if enabled. If a DLQ is not enabled, a log message will be emitted, and the event will be dropped. See [DLQ Policy](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-dlq-policy) for more info.
> - 409 errors (conflict) are logged as a warning and dropped.

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [May 27, 2022, 1:13pm UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/12 "2022-05-27T13:13:01Z")

</div>

Many thanks for point out the answer

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2022, 1:13pm UTC](https://discuss.elastic.co/t/last-failure-timestamp/305591/13 "2022-06-24T13:13:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
