# Logstash in Docker and Elastic down

**URL:** <https://discuss.elastic.co/t/logstash-in-docker-and-elastic-down/322675>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [January 8, 2023, 8:59am UTC](https://discuss.elastic.co/t/logstash-in-docker-and-elastic-down/322675 "2023-01-08T08:59:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hofrichterovak](https://avatars.discourse-cdn.com/v4/letter/h/ba9def/32.png) [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Post date:** [January 8, 2023, 8:59am UTC](https://discuss.elastic.co/t/logstash-in-docker-and-elastic-down/322675/1 "2023-01-08T08:59:54Z")

</div>

Hello,

I'm running Logstash in Docker. Sometimes it happens that Elasticsearch is unavailable and when I restart the Logstash docker container, Logstash removing messages are they are no longer saved to Elasticsearch.

I would like to ask where does Logstash store the logs that failed to be sent to Elasticsearch (Elasticsearch is not available)?

I would like Logstash to keep the logs even after restarting the Logstash container. When I set up a dead letter queue, messages were not saved there.

Please, what should I set? 🙂

Thank you,  
Katerina

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 8, 2023, 11:44am UTC](https://discuss.elastic.co/t/logstash-in-docker-and-elastic-down/322675/2 "2023-01-08T11:44:38Z")

</div>

> [@hofrichterovak](#):
>
> I would like to ask where does Logstash store the logs that failed to be sent to Elasticsearch (Elasticsearch is not available)?

Per default logstash uses a [memory queue](https://www.elastic.co/guide/en/logstash/current/memory-queue.html), so if you restart Logstash it will lose the messages.

> [@hofrichterovak](#):
>
> I would like Logstash to keep the logs even after restarting the Logstash container.

You need to use [persistent queues](https://www.elastic.co/guide/en/logstash/current/persistent-queues.html), to use this with a docker container you will need a volume that persists during container restarts.

> [@hofrichterovak](#):
>
> When I set up a dead letter queue, messages were not saved there.

This is correct, the [dead letter queue](https://www.elastic.co/guide/en/logstash/current/dead-letter-queues.html#dead-letter-queues) only works when it got a response of `400` or `404` from Elasticsearch, if Elasticsearch is down, the dead letter queue won't intercept the message.

From the documentation you have this information:

> **HTTP request failure.** If the HTTP request fails (because Elasticsearch is unreachable or because it returned an HTTP error code), the Elasticsearch output retries the entire request indefinitely. In these scenarios, the dead letter queue has no opportunity to intercept.

---

<div class="post-metadata">

**Author:** ![hofrichterovak](https://avatars.discourse-cdn.com/v4/letter/h/ba9def/32.png) [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Post date:** [January 9, 2023, 9:06am UTC](https://discuss.elastic.co/t/logstash-in-docker-and-elastic-down/322675/3 "2023-01-09T09:06:38Z")

</div>

Hello,

I didn´t know it. I set up the persistence queue and it works now. 🙂

Thank you,  
Katerina

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2023, 9:07am UTC](https://discuss.elastic.co/t/logstash-in-docker-and-elastic-down/322675/4 "2023-02-06T09:07:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
