# Live config reload

**URL:** https://discuss.elastic.co/t/live-config-reload/39611
**Category:** Logstash
**Created:** [January 20, 2016, 2:50am UTC](https://discuss.elastic.co/t/live-config-reload/39611 "2016-01-20T02:50:24Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![TigranTsat](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@TigranTsat](https://discuss.elastic.co/u/TigranTsat)
#### Post date: [January 20, 2016, 2:50am UTC](https://discuss.elastic.co/t/live-config-reload/39611/1 "2016-01-20T02:50:24Z")

</div>

Hello.

Looks like currently there is no way for config live reload (please, correct me if I am wrong). And the only option is to shutdown logstash and start it again.  
In that case, question - how much logs I will loose if I have pipeline that reads from file and sends to elasticsearch. My understanding is:

1. File pointer is being saved, so no log messages duplication or loss.  
1.a If log file got rotated while logstash is down - messages are being lost from remaining rotated file.  
1.b In case of rotation, will there be conflict with saved pointer to file position
2. Probably small amount of messages being lost from internal logstash queue
3. Messages that are subject to shipping or in the middle of shipping to elasticsearch are also being lost.

Am I correct?

What are the options to prevent log loss and allow to add new files to config at runtime?

Thank you.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [January 20, 2016, 4:04am UTC](https://discuss.elastic.co/t/live-config-reload/39611/2 "2016-01-20T04:04:31Z")

</div>

It has an internal "cache" of 40 items that will probably be dropped.  
The next major version is slated to add functionality to assist with this.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [January 20, 2016, 4:44am UTC](https://discuss.elastic.co/t/live-config-reload/39611/3 "2016-01-20T04:44:02Z")

</div>

With the revamped pipeline flush in Logstash 2.0 (I think) it don't think the two internal 20-item queues will be lost. The only thing I'd worry about is file rotations. Sadly the file input documentation isn't too specific about what happens.

---

<div class="post-metadata">

### Author: ![TigranTsat](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@TigranTsat](https://discuss.elastic.co/u/TigranTsat)
#### Post date: [January 20, 2016, 3:05pm UTC](https://discuss.elastic.co/t/live-config-reload/39611/4 "2016-01-20T15:05:55Z")

</div>

Thank you very much  
Is there a documentation of that feature for next release?  
When next release will happen?

Question on the side: If internal queues are 20 items long. How bulk insert works for elasticsearch? It is 40 items bulk?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [January 20, 2016, 3:09pm UTC](https://discuss.elastic.co/t/live-config-reload/39611/5 "2016-01-20T15:09:26Z")

</div>

> Is there a documentation of that feature for next release?

There's a roadmap page in the online documentation.

> Question on the side: If internal queues are 20 items long. How bulk insert works for elasticsearch? It is 40 items bulk?

No, the elasticsearch output has its own buffer. But yes, those messages are also in the jackpot if Logstash is shut down abruptly without being given an opportunity to shut down cleanly.

---

<div class="post-metadata">

### Author: ![TigranTsat](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@TigranTsat](https://discuss.elastic.co/u/TigranTsat)
#### Post date: [January 20, 2016, 3:23pm UTC](https://discuss.elastic.co/t/live-config-reload/39611/6 "2016-01-20T15:23:50Z")

</div>

But I guess, if I shutdown it with 'SIGTERM' ([http://stackoverflow.com/questions/29742313/clean-way-to-stop-logstash](http://stackoverflow.com/questions/29742313/clean-way-to-stop-logstash)) it should be ok.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [January 20, 2016, 6:36pm UTC](https://discuss.elastic.co/t/live-config-reload/39611/7 "2016-01-20T18:36:35Z")

</div>

Yes, at least if Logstash is able to flush the pipeline. If an output is blocked then Logstash won't shut down, which is something you might need to deal with.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:15am UTC](https://discuss.elastic.co/t/live-config-reload/39611/8 "2017-07-06T05:15:01Z")

</div>


