# Logstash Dead Letter Queue

**URL:** <https://discuss.elastic.co/t/logstash-dead-letter-queue/174093>\
**Category:** Logstash\
**Created:** [March 27, 2019, 10:35am UTC](https://discuss.elastic.co/t/logstash-dead-letter-queue/174093 "2019-03-27T10:35:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![wiliamauc85](https://avatars.discourse-cdn.com/v4/letter/w/bc8723/32.png) [@wiliamauc85](https://discuss.elastic.co/u/wiliamauc85)\
**Post date:** [March 27, 2019, 10:35am UTC](https://discuss.elastic.co/t/logstash-dead-letter-queue/174093/1 "2019-03-27T10:35:39Z")

</div>

Hi,

I've been trying to setup a dead letter queue

`> [WARN] 2019-03-27 10:19:14.917 [[main]>worker0] elasticsearch - Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"hpc-wa-2019.03.06", :_type=>"doc", :routing=>nil}, #<LogStash::Event:0x10a2bd76>], :response=>{"index"=>{"_index"=>"hpc-wa-2019.03.06", "_type"=>"doc", "_id"=>"syipvmkB7zoe6E2bN46B", "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"mapper [0] of different type, current_type [text], merged_type [ObjectMapper]"}}}}`

So Logstash is outputting to Elastic with an error 400

dead\_letter\_queue.enable: true  
path.dead\_letter\_queue: /usr/share/logstash/data/dead\_letter\_queue

However it's not creating the DLQ log file

Checking the Logstash log, it mentioned that dead\_letter\_queue directory wasn't writable so I changed the permissions, but still no log file, is there something else I'm missing?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2019, 10:35am UTC](https://discuss.elastic.co/t/logstash-dead-letter-queue/174093/2 "2019-04-24T10:35:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
