That's unusual. I don't think the elasticsearch output plugin is capable of dropping events when ES is down so it takes a more complicated setup. I'm actually not sure how that would be done. It's a lot easier to construct something where the elasticsearch output would pick up the events it has missed; just have two Kafka consumers in different Logstash pipelines. They'll consume from Kafka independently and won't affect each other.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.