# Logstash data transit time and possible line loss before elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-data-transit-time-and-possible-line-loss-before-elasticsearch/195451>\
**Category:** Logstash\
**Created:** [August 16, 2019, 8:04am UTC](https://discuss.elastic.co/t/logstash-data-transit-time-and-possible-line-loss-before-elasticsearch/195451 "2019-08-16T08:04:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Igorr](https://avatars.discourse-cdn.com/v4/letter/i/77aa72/32.png) [@Igorr](https://discuss.elastic.co/u/Igorr)\
**Post date:** [August 16, 2019, 8:04am UTC](https://discuss.elastic.co/t/logstash-data-transit-time-and-possible-line-loss-before-elasticsearch/195451/1 "2019-08-16T08:04:39Z")

</div>

Data on time leaves logstash (tracked by tcpdump) and is delayed in kibana.  
What monitoring tools are best used to track at what stage data is delayed?

There are no errors in logstash logs. To check for possible loss of rows from sql queries, added row numbers. Built a graph of timestamp versus row\_number, everything is fine here.  
What else can be done in logstash?

---

<div class="post-metadata">

**Author:** ![Igorr](https://avatars.discourse-cdn.com/v4/letter/i/77aa72/32.png) [@Igorr](https://discuss.elastic.co/u/Igorr)\
**Post date:** [August 16, 2019, 6:34pm UTC](https://discuss.elastic.co/t/logstash-data-transit-time-and-possible-line-loss-before-elasticsearch/195451/2 "2019-08-16T18:34:49Z")

</div>

There were delays in receiving data due to the suboptimal index.refresh\_interval parameter

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2019, 6:34pm UTC](https://discuss.elastic.co/t/logstash-data-transit-time-and-possible-line-loss-before-elasticsearch/195451/3 "2019-09-13T18:34:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
