# Logsstash and apache kafka

**URL:** <https://discuss.elastic.co/t/logsstash-and-apache-kafka/307559>\
**Category:** Logstash\
**Created:** [June 18, 2022, 9:59am UTC](https://discuss.elastic.co/t/logsstash-and-apache-kafka/307559 "2022-06-18T09:59:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Henk\_Stobbe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/henk_stobbe/32/88015_2.png) [@Henk\_Stobbe](https://discuss.elastic.co/u/Henk_Stobbe)\
**Post date:** [June 18, 2022, 9:59am UTC](https://discuss.elastic.co/t/logsstash-and-apache-kafka/307559/1 "2022-06-18T09:59:12Z")

</div>

hello,

Newbee so maybe strange question. In my enviroments Kafka is used and the main reason for this is the ability to temporaly queue data. This functionality is (now) available in logstash.  
So simple question, can we remove kafka?  
I understand that you can also look at this the “micro service way” and still favor a spit in manipulation fase and a data director fase, but a container/logstash/volume looks to me the optimum solution?

Please comment. KR Henk

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 18, 2022, 2:14pm UTC](https://discuss.elastic.co/t/logsstash-and-apache-kafka/307559/2 "2022-06-18T14:14:06Z")

</div>

> [@Henk\_Stobbe](#):
>
> In my enviroments Kafka is used and the main reason for this is the ability to temporaly queue data. This functionality is (now) available in logstash.

Can you give context on this? Kafka and Logstash are two completely different tools with completely different use cases.

What is the functionality that you say that Logstash have now?

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [June 18, 2022, 3:43pm UTC](https://discuss.elastic.co/t/logsstash-and-apache-kafka/307559/3 "2022-06-18T15:43:16Z")

</div>

if you are running a large enterprise data ingestion/aggregation system, then an Event Bus like Kafka is highly recommended. Some reasons include

- the downstream systems like Logstash/elastic or other 3rd party system may need restarting or updates frequently. This means you may loose data from UDP/TCP/streaming systems
- Event Bus (kafka) acts as buffering layer and smoothes the data into Elastic or downstream systems. The "velocity" & "veracity" of data is made much better using Event Bus
- Other systems can get the data from Kafka without bothering your team
- lot other reasons too

Overall it depends on the design/architecture of your platform and how much data resiliency you require

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 18, 2022, 3:53pm UTC](https://discuss.elastic.co/t/logsstash-and-apache-kafka/307559/4 "2022-06-18T15:53:03Z")

</div>

The big difference is that the persistent queue functionality in Logstash is specific to each node and does not run in clustered mode. If you lose a node you may therefore lose data. Kafka however supports running in clustered node and losing a node does generally not lead to data loss, and is therefore generally more resilient.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2022, 3:53pm UTC](https://discuss.elastic.co/t/logsstash-and-apache-kafka/307559/5 "2022-07-16T15:53:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
