# Loadbalancing with syslog

**URL:** <https://discuss.elastic.co/t/loadbalancing-with-syslog/66361>\
**Category:** Logstash\
**Created:** [November 17, 2016, 10:07am UTC](https://discuss.elastic.co/t/loadbalancing-with-syslog/66361 "2016-11-17T10:07:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [November 17, 2016, 10:07am UTC](https://discuss.elastic.co/t/loadbalancing-with-syslog/66361/1 "2016-11-17T10:07:54Z")

</div>

Hi !

I use a syslog server which sends log to my cluster (3 servers cluster). Each server has a logstash instance.  
The syslog server send only to 2 servers.

I found that my entries are doubled and I think it's because the syslog server send the same logs to the two servers.

So I would like to know if there is a way to send to only one IP which will send to the three logstash servers. I thought about redis but I've nerver used it and don't know how it works.

Thanks for your help !

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [November 17, 2016, 12:44pm UTC](https://discuss.elastic.co/t/loadbalancing-with-syslog/66361/2 "2016-11-17T12:44:36Z")

</div>

You will have to set up some kind of Load Balancer, if Syslog does not support something like this

Fortunately your dealing with syslog which can do TCP or UDP Connections

You could try a few options, I use Hardware like an F5 but any hardware would work

But you can do it in software too  
[http://haproxy.com/](http://haproxy.com/) (TCP or UDP)  
Apache (TCP only I think)  
Nginx [https://www.nginx.com/resources/admin-guide/tcp-load-balancing/](https://www.nginx.com/resources/admin-guide/tcp-load-balancing/) (or udp)

Probably the easiest but most technical

Iptables  
[http://lartc.org/autoloadbalance.htmlroxy](http://lartc.org/autoloadbalance.htmlroxy)

Other then that a little googling will go a long long way.

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [November 17, 2016, 12:58pm UTC](https://discuss.elastic.co/t/loadbalancing-with-syslog/66361/3 "2016-11-17T12:58:50Z")

</div>

In fact I'm trying something totally different.

I only put one logstash instance, every logs will be send to it and the output of the config files will do the loadbalancing (I wrote de name of the different elasticsearch hosts)

I think it's a good solution to my problem.

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [November 17, 2016, 1:04pm UTC](https://discuss.elastic.co/t/loadbalancing-with-syslog/66361/4 "2016-11-17T13:04:14Z")

</div>

Great

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2016, 1:05pm UTC](https://discuss.elastic.co/t/loadbalancing-with-syslog/66361/5 "2016-12-15T13:05:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
