# Logstash forwarder, logstash, nxlog, redis, which one to use?

**URL:** <https://discuss.elastic.co/t/logstash-forwarder-logstash-nxlog-redis-which-one-to-use/26220>\
**Category:** Logstash\
**Created:** [July 24, 2015, 8:24am UTC](https://discuss.elastic.co/t/logstash-forwarder-logstash-nxlog-redis-which-one-to-use/26220 "2015-07-24T08:24:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![zpp](https://avatars.discourse-cdn.com/v4/letter/z/54ee81/32.png) [@zpp](https://discuss.elastic.co/u/zpp)\
**Post date:** [July 24, 2015, 8:24am UTC](https://discuss.elastic.co/t/logstash-forwarder-logstash-nxlog-redis-which-one-to-use/26220/1 "2015-07-24T08:24:03Z")

</div>

when i started to play with ELK, i followed some article and setup elk like this: logstash -\> redis -\> logstash -\> elastic search -\> kibana. I'm prepared that logstash shipper will use more memory, but i wasn't prepared that it'll use a noticeable amount of CPU as well: the java.exe used 10-20% cpu (windows, monitors one folder with about 50 files inside updated constantly), which is a lot and out of consideration. I need something has a minimal footprint on the application server, which can be either windows or linux, and with the consideration of scalability and data integrity, what kind of architecture should I go for? thank you.

---

<div class="post-metadata">

**Author:** ![PatrickKik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrickkik/32/619_2.png) [@PatrickKik](https://discuss.elastic.co/u/PatrickKik)\
**Post date:** [July 24, 2015, 11:52am UTC](https://discuss.elastic.co/t/logstash-forwarder-logstash-nxlog-redis-which-one-to-use/26220/2 "2015-07-24T11:52:03Z")

</div>

You are describing pretty much a standard setup that is widely used. You might want to look into Beats, one of the Elastic products.

---

<div class="post-metadata">

**Author:** ![zpp](https://avatars.discourse-cdn.com/v4/letter/z/54ee81/32.png) [@zpp](https://discuss.elastic.co/u/zpp)\
**Post date:** [July 27, 2015, 3:36am UTC](https://discuss.elastic.co/t/logstash-forwarder-logstash-nxlog-redis-which-one-to-use/26220/3 "2015-07-27T03:36:32Z")

</div>

Looks like FileBeat is not yet ready.

About logstash forwarder, if logstash is too busy to take care of the incoming data , will forwarder slow down its pace in sending the data?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 27, 2015, 8:28pm UTC](https://discuss.elastic.co/t/logstash-forwarder-logstash-nxlog-redis-which-one-to-use/26220/4 "2015-07-27T20:28:08Z")

</div>

Yes, logstash-forwarder will back off nicely.

---

<div class="post-metadata">

**Author:** ![zpp](https://avatars.discourse-cdn.com/v4/letter/z/54ee81/32.png) [@zpp](https://discuss.elastic.co/u/zpp)\
**Post date:** [July 28, 2015, 5:59am UTC](https://discuss.elastic.co/t/logstash-forwarder-logstash-nxlog-redis-which-one-to-use/26220/5 "2015-07-28T05:59:40Z")

</div>

in this case, logstash-forwarder -\> logstash -\> elasticsearch vs. logstash-\>redis-\>logstash-\>elasticsearch, which one will you reommend? what are the pros/cons for each approach?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 28, 2015, 7:57am UTC](https://discuss.elastic.co/t/logstash-forwarder-logstash-nxlog-redis-which-one-to-use/26220/6 "2015-07-28T07:57:50Z")

</div>

I'd say it doesn't matter that much. Having a buffer in between means that messages can be shipped off of the leaf machine as quickly as possible, but you also get a more complicated setup. The main advantage of having a buffer is really if you have inputs that don't back off in a good way but that's not the case for you.

---

<div class="post-metadata">

**Author:** ![zpp](https://avatars.discourse-cdn.com/v4/letter/z/54ee81/32.png) [@zpp](https://discuss.elastic.co/u/zpp)\
**Post date:** [July 28, 2015, 12:21pm UTC](https://discuss.elastic.co/t/logstash-forwarder-logstash-nxlog-redis-which-one-to-use/26220/7 "2015-07-28T12:21:41Z")

</div>

I see, thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:33am UTC](https://discuss.elastic.co/t/logstash-forwarder-logstash-nxlog-redis-which-one-to-use/26220/8 "2017-07-06T05:33:36Z")

</div>


