# Load Balancing and Roaming with Winlogbeat

**URL:** <https://discuss.elastic.co/t/load-balancing-and-roaming-with-winlogbeat/205071>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 24, 2019, 1:08pm UTC](https://discuss.elastic.co/t/load-balancing-and-roaming-with-winlogbeat/205071 "2019-10-24T13:08:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bosand](https://avatars.discourse-cdn.com/v4/letter/b/b4bc9f/32.png) [@bosand](https://discuss.elastic.co/u/bosand)\
**Post date:** [October 24, 2019, 1:08pm UTC](https://discuss.elastic.co/t/load-balancing-and-roaming-with-winlogbeat/205071/1 "2019-10-24T13:08:37Z")

</div>

Hi,

I would like to know whether Winlogbeat supports the following use case:  
Suppose I have 1000 machines that are configured with 2 Logstash output hosts A and B.  
I would like all traffic to be sent to A. When A becomes unreachable, traffic should be sent to B.  
Documentation says hosts are picked **randomly** for connections. Is there a workaround to implement prioritization?  
With the current configuration, it cannot be predicted how many machines would send logs to host A and how many to host B if both are reachable.

If I set the **loadbalance** flag to **true** , what would happen when host A becomes unresponsive? Would Winlogbeat redirect ALL messages to host B? If yes, how frequently would it try to re-establish a connection with host A to restore load balancing?

Thanks!

---

<div class="post-metadata">

**Author:** ![pmercado](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@pmercado](https://discuss.elastic.co/u/pmercado)\
**Post date:** [October 25, 2019, 11:17am UTC](https://discuss.elastic.co/t/load-balancing-and-roaming-with-winlogbeat/205071/2 "2019-10-25T11:17:21Z")

</div>

There doesn't seem to be a way of controlling LB from a beat to multiple output

Probably the closer you can get is seting up both outputs (logstash), and also setting `max_tries` above the default

```auto
  # The number of times a particular Elasticsearch index operation is attempted. If
  # the indexing operation doesn't succeed after this many retries, the events are
  # dropped. The default is 3.
  #max_retries: 3

```

Some requests will still try to hit the non responding output endpoint though. The alternative is using some sort of external proxy, mesh like, that load balances the beat's output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2019, 11:17am UTC](https://discuss.elastic.co/t/load-balancing-and-roaming-with-winlogbeat/205071/3 "2019-11-22T11:17:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
