# Logstash instance slave failover

**URL:** <https://discuss.elastic.co/t/logstash-instance-slave-failover/76418>\
**Category:** Logstash\
**Created:** [February 24, 2017, 3:43pm UTC](https://discuss.elastic.co/t/logstash-instance-slave-failover/76418 "2017-02-24T15:43:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![SuperbBug](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@SuperbBug](https://discuss.elastic.co/u/SuperbBug)\
**Post date:** [February 24, 2017, 3:43pm UTC](https://discuss.elastic.co/t/logstash-instance-slave-failover/76418/1 "2017-02-24T15:43:23Z")

</div>

Does someone knows how to scale Logstash? What do I mean by scaling? Let's say I have one instance of Logstash producing messages from jdbc to Kafka and lets say that node where Logstash service is installed and instance of him is running fall down suddenly.

How to continue with the same process, something like master-slave config? Is there any way to acomplish that or I need to set some work around by myself?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 27, 2017, 12:56pm UTC](https://discuss.elastic.co/t/logstash-instance-slave-failover/76418/2 "2017-02-27T12:56:18Z")

</div>

The jdbc input doesn't support sharing its state file with another instance, so there's no official support for having two instances running at the same time if they're using a jdbc input.

However, if you can verify that the instance is down, you can point another Logstash instance to the same state file and have it continue roughly at the same place where the first instance stopped.

I wouldn't call this "scaling", by the way.

---

<div class="post-metadata">

**Author:** ![SuperbBug](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@SuperbBug](https://discuss.elastic.co/u/SuperbBug)\
**Post date:** [February 27, 2017, 1:32pm UTC](https://discuss.elastic.co/t/logstash-instance-slave-failover/76418/3 "2017-02-27T13:32:01Z")

</div>

Is there anything implemented to "heartbeat" the logstash instances or I need to implemented by myself? Any suggestions? Maybe firebeat?

And thank you for the response 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 27, 2017, 1:35pm UTC](https://discuss.elastic.co/t/logstash-instance-slave-failover/76418/4 "2017-02-27T13:35:28Z")

</div>

What kind of heartbeat do you need? Recent versions of Logstash has a monitoring API, or you could use an output plugin of your choice to ping something for each processed event. [Lovebeat](https://github.com/boivie/lovebeat) can help you figure out when heartbeats have stopped arriving.

See also [https://www.elastic.co/blog/how-to-check-logstashs-pulse](https://www.elastic.co/blog/how-to-check-logstashs-pulse).

---

<div class="post-metadata">

**Author:** ![SuperbBug](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@SuperbBug](https://discuss.elastic.co/u/SuperbBug)\
**Post date:** [February 27, 2017, 1:36pm UTC](https://discuss.elastic.co/t/logstash-instance-slave-failover/76418/5 "2017-02-27T13:36:41Z")

</div>

Something like kafka group managment. If I quote you "_if you can verify that the instance is down, you can point another Logstash instance to the same state file and have it continue roughly at the same place where the first instance stopped._". I need exactly this

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 27, 2017, 1:46pm UTC](https://discuss.elastic.co/t/logstash-instance-slave-failover/76418/6 "2017-02-27T13:46:21Z")

</div>

And there's no built-in support for that.

---

<div class="post-metadata">

**Author:** ![SuperbBug](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@SuperbBug](https://discuss.elastic.co/u/SuperbBug)\
**Post date:** [February 27, 2017, 1:48pm UTC](https://discuss.elastic.co/t/logstash-instance-slave-failover/76418/7 "2017-02-27T13:48:40Z")

</div>

You can suggest me something?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2017, 1:48pm UTC](https://discuss.elastic.co/t/logstash-instance-slave-failover/76418/8 "2017-03-27T13:48:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
