# Logstash is failing if one of the ES is down

**URL:** https://discuss.elastic.co/t/logstash-is-failing-if-one-of-the-es-is-down/92639
**Category:** Logstash
**Created:** [July 11, 2017, 12:10pm UTC](https://discuss.elastic.co/t/logstash-is-failing-if-one-of-the-es-is-down/92639 "2017-07-11T12:10:44Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Narayanan\_Sukumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/narayanan_sukumar/32/19546_2.png) [@Narayanan\_Sukumar](https://discuss.elastic.co/u/Narayanan_Sukumar)
#### Post date: [July 11, 2017, 12:10pm UTC](https://discuss.elastic.co/t/logstash-is-failing-if-one-of-the-es-is-down/92639/1 "2017-07-11T12:10:44Z")

</div>

I was doing some testing with my ELK setup before it is going into production.

I have two ES clusters and based on the kafka topic it will push.

I intentionally made the one of the ES down and the logstash is not pushing the request for the another working kafka topic to the working ES.

# What should I need to do here to have full uptime and have a better degradation mode processing?

# Ansible managed

output {

if [type\_name] == "topic1" {  
elasticsearch {  
hosts =\> ["es1"] ### \<\<\<\< THIS IS THE ES CLUSTER THAT I MADE DOWN  
index =\> "%{[type\_name]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[type\_name]}"  
}  
}  
if [type\_name] == "topic2" {  
elasticsearch {  
hosts =\> ["es2"]  
index =\> "%{[type\_name]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[type\_name]}"  
}  
}  
if [type\_name] == "topic3" {  
elasticsearch {  
hosts =\> ["es3"]  
index =\> "%{[type\_name]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[type\_name]}"  
}  
}  
if [type\_name] == "topic4" {  
elasticsearch {  
hosts =\> ["es4"]  
index =\> "%{[type\_name]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[type\_name]}"  
}  
}  
if [type\_name] == "nginx" {  
elasticsearch {  
hosts =\> ["[search-nginx-msvbrtx3cnxthe2ttezqmrrm3m.ap-southeast-1.es.amazonaws.com:80](http://search-nginx-msvbrtx3cnxthe2ttezqmrrm3m.ap-southeast-1.es.amazonaws.com:80)"]  
index =\> "%{[type\_name]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[type\_name]}"  
}  
}

}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 11, 2017, 2:55pm UTC](https://discuss.elastic.co/t/logstash-is-failing-if-one-of-the-es-is-down/92639/2 "2017-07-11T14:55:58Z")

</div>

Is es1 the name of a single host or the address of a loadbalancer that distributes requests across multiple ES nodes?

If one output is blocked Logstash's event pipeline grinds to a halt until the output becomes available.

---

<div class="post-metadata">

### Author: ![Narayanan\_Sukumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/narayanan_sukumar/32/19546_2.png) [@Narayanan\_Sukumar](https://discuss.elastic.co/u/Narayanan_Sukumar)
#### Post date: [July 12, 2017, 4:55am UTC](https://discuss.elastic.co/t/logstash-is-failing-if-one-of-the-es-is-down/92639/3 "2017-07-12T04:55:44Z")

</div>

> [@magnusbaeck](#):
>
> If one output is blocked Logstash's event pipeline grinds to a halt until the output becomes available.

Agree!. But it should not affect the other outputs plugins. Or can we have any fall back output if one of the cluster is down(Based on the healthcheck).

> [@magnusbaeck](#):
>
> Is es1 the name of a single host or the address of a loadbalancer that distributes requests across multiple ES nodes?

Elasticsearch endpoint from AWS and it is a clustered one.

Thanks and BR,  
Narayanan

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 12, 2017, 9:17am UTC](https://discuss.elastic.co/t/logstash-is-failing-if-one-of-the-es-is-down/92639/4 "2017-07-12T09:17:52Z")

</div>

> Agree!. But it should not affect the other outputs plugins.

But it does. The whole pipeline stalls.

> Or can we have any fall back output if one of the cluster is down(Based on the healthcheck).

No, unless the new dead letter queue feature can help out. I haven't looked into it much.

---

<div class="post-metadata">

### Author: ![Narayanan\_Sukumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/narayanan_sukumar/32/19546_2.png) [@Narayanan\_Sukumar](https://discuss.elastic.co/u/Narayanan_Sukumar)
#### Post date: [July 13, 2017, 10:21am UTC](https://discuss.elastic.co/t/logstash-is-failing-if-one-of-the-es-is-down/92639/5 "2017-07-13T10:21:10Z")

</div>

Thank You 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 10, 2017, 10:21am UTC](https://discuss.elastic.co/t/logstash-is-failing-if-one-of-the-es-is-down/92639/6 "2017-08-10T10:21:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
