# Logstash file output - persisted queue option?

**URL:** https://discuss.elastic.co/t/logstash-file-output-persisted-queue-option/132233
**Category:** Logstash
**Created:** [May 17, 2018, 12:56am UTC](https://discuss.elastic.co/t/logstash-file-output-persisted-queue-option/132233 "2018-05-17T00:56:53Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![bloke](https://avatars.discourse-cdn.com/v4/letter/b/b5e925/32.png) [@bloke](https://discuss.elastic.co/u/bloke)
#### Post date: [May 17, 2018, 12:56am UTC](https://discuss.elastic.co/t/logstash-file-output-persisted-queue-option/132233/1 "2018-05-17T00:56:53Z")

</div>

Hi,

I am wondering, currently I have logstash writing file output and doing ES like such

```
output {
    if (([type] =~ /^srx$/) and ("noelastic" not in [tags])) {
                elasticsearch
                {
                 hosts => ["hosts:9200"]
                 index => "srx-%{+YYYY.MM.dd}"
                }
        }
        if ([type] =~ /^srx$/) and ("nosavelogs" not in [tags]) {
                file {
                path => "/logstash-data/nfs-service/srx/%{host}-%{+YYYY-MM-dd}.txt"
                codec => line { format => "%{message}" }
                }
        }
}

```

If my NFS (purestorage flashblade) service malfunctions logstash restarts and will recreate the file structure and files on the local disk.

Is there a way to instruct logstash that if file output is obstructed or blocked to fallback to logstashes persisted queuing? this would be preferable for me as i have already designed adequate PQ disk space to be available across a number of LS servers.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 14, 2018, 12:56am UTC](https://discuss.elastic.co/t/logstash-file-output-persisted-queue-option/132233/2 "2018-06-14T00:56:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
