# Logging events lost when Elastic Search connection goes down

**URL:** <https://discuss.elastic.co/t/logging-events-lost-when-elastic-search-connection-goes-down/47801>\
**Category:** Logstash\
**Created:** [April 19, 2016, 2:41pm UTC](https://discuss.elastic.co/t/logging-events-lost-when-elastic-search-connection-goes-down/47801 "2016-04-19T14:41:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ono](https://avatars.discourse-cdn.com/v4/letter/o/b19c9b/32.png) [@ono](https://discuss.elastic.co/u/ono)\
**Post date:** [April 19, 2016, 2:41pm UTC](https://discuss.elastic.co/t/logging-events-lost-when-elastic-search-connection-goes-down/47801/1 "2016-04-19T14:41:39Z")

</div>

Guys,

We're trying filebeat, forwarding logs to logstash (for JSON parsing) and then onwards into Elastic Search (ES). One of the scenarios we're testing is connection between logstash and ES going down and then the logstash service being terminated.

In this scenarios, log events buffered in logstash are lost. Can someone confirm that's the expecetd behaviour and whether we can work around it, or minimize the loss somehow ?

Thanks,  
ONO

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 19, 2016, 6:15pm UTC](https://discuss.elastic.co/t/logging-events-lost-when-elastic-search-connection-goes-down/47801/2 "2016-04-19T18:15:46Z")

</div>

LS currently doesn't persist its internal queue. Until it does I don't see how you can completely eliminate the risk of LS losing any messages.

---

<div class="post-metadata">

**Author:** ![ono](https://avatars.discourse-cdn.com/v4/letter/o/b19c9b/32.png) [@ono](https://discuss.elastic.co/u/ono)\
**Post date:** [April 20, 2016, 8:38am UTC](https://discuss.elastic.co/t/logging-events-lost-when-elastic-search-connection-goes-down/47801/3 "2016-04-20T08:38:18Z")

</div>

Is there a way to minimize it maybe? By stopping the beats listener when the upstream has closed or any other suggestion?

I've come across the congestion\_threshold parameter, how does that work?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:01am UTC](https://discuss.elastic.co/t/logging-events-lost-when-elastic-search-connection-goes-down/47801/4 "2017-07-06T05:01:30Z")

</div>


