# Logstash failover s3

**URL:** <https://discuss.elastic.co/t/logstash-failover-s3/69037>\
**Category:** Logstash\
**Created:** [December 14, 2016, 3:17pm UTC](https://discuss.elastic.co/t/logstash-failover-s3/69037 "2016-12-14T15:17:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bob-bza](https://avatars.discourse-cdn.com/v4/letter/b/9f8e36/32.png) [@bob-bza](https://discuss.elastic.co/u/bob-bza)\
**Post date:** [December 14, 2016, 3:17pm UTC](https://discuss.elastic.co/t/logstash-failover-s3/69037/1 "2016-12-14T15:17:18Z")

</div>

i was planning to pull elb logs from s3 using logstash. i want to use multiple logstash for failover control. is there anything i can use multiple logstash to pull logs from s3 bucket with loadbalance or something else can configure.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 18, 2016, 8:55pm UTC](https://discuss.elastic.co/t/logstash-failover-s3/69037/2 "2016-12-18T20:55:47Z")

</div>

This is tricky to do without a single point of failure since Logstash's s3 input doesn't support sharing state with multiple Logstash instances.

What, _exactly_, do you want to accomplish? What's the scenario?

---

<div class="post-metadata">

**Author:** ![bob-bza](https://avatars.discourse-cdn.com/v4/letter/b/9f8e36/32.png) [@bob-bza](https://discuss.elastic.co/u/bob-bza)\
**Post date:** [December 19, 2016, 3:12pm UTC](https://discuss.elastic.co/t/logstash-failover-s3/69037/3 "2016-12-19T15:12:22Z")

</div>

i was planning to send elb logs to s3 and there to elasticsearch using logstash.  
My concern was about if logstash node failed or something happen to log at that time i was looking for highavailability like using 2 logstash nodes if node1 fails we have node 2

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 20, 2016, 6:49am UTC](https://discuss.elastic.co/t/logstash-failover-s3/69037/4 "2016-12-20T06:49:22Z")

</div>

Okay. Well, as I said the s3 input can't share state between multiple Logstash instances so whatever you do you won't really get any help from Logstash. Since logs are naturally buffered in S3 I wouldn't worry too much about Logstash going down. Just prepare routines and/or scripts to sync state from one Logstash instance to another and be prepared to fire up a new instance that can start with the state of the old dead instance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2017, 6:49am UTC](https://discuss.elastic.co/t/logstash-failover-s3/69037/5 "2017-01-17T06:49:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
