# Logstash Indexer High Availability

**URL:** <https://discuss.elastic.co/t/logstash-indexer-high-availability/57701>\
**Category:** Logstash\
**Created:** [August 10, 2016, 11:56am UTC](https://discuss.elastic.co/t/logstash-indexer-high-availability/57701 "2016-08-10T11:56:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![harrytewkesbury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harrytewkesbury/32/11010_2.png) [@harrytewkesbury](https://discuss.elastic.co/u/harrytewkesbury)\
**Post date:** [August 10, 2016, 11:56am UTC](https://discuss.elastic.co/t/logstash-indexer-high-availability/57701/1 "2016-08-10T11:56:12Z")

</div>

Hi,

I have seen a few older solutions for HA with logstash, and wonder if they hold true still. The official documentation on scaling up logstash ([Deploying and Scaling Logstash | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/deploying-and-scaling.html)) shows multiple queues, and/or multiple shippers, but only one indexing instance. Near the end it states

> Alternately, increase the Elasticsearch cluster’s rate of data consumption by adding more Logstash indexing instances.

However there are no suggestions as to how best to do this. If I have, say, 10 clients all shipping logs, do I simply use the load balancing config flag in filebeat? Must I have a separate tier for shipping logs to another logstash layer/redis layer?

Any recommendations would be great. Resources to use are relatively slim, but log ingestion rate on our current single node stack is around 800 events/second but we'd be looking to scale that up possibly by up to 10x over the coming months, so a degree of breathing room would be helpful.

In any case, this is more about HA than load balancing, so whatever you think is best would be interesting to read. Thanks in advance.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 10, 2016, 8:58pm UTC](https://discuss.elastic.co/t/logstash-indexer-high-availability/57701/2 "2016-08-10T20:58:50Z")

</div>

In these sorts of situations you'd have a receiving instance that puts things into a broker (kafka etc) and then have the indexers between that and ES.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:43am UTC](https://discuss.elastic.co/t/logstash-indexer-high-availability/57701/3 "2017-07-06T04:43:55Z")

</div>


