# Logstash output for multiple elasticsearch instance

**URL:** <https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194>\
**Category:** Logstash\
**Created:** [June 9, 2015, 8:34am UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194 "2015-06-09T08:34:24Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![saif](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saif/32/37431_2.png) [@saif](https://discuss.elastic.co/u/saif)\
**Post date:** [June 9, 2015, 8:34am UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194/1 "2015-06-09T08:34:24Z")

</div>

hello  
i m working to collect logs from 3000 server  
I installed 2 servers with ElasticSearch and logstash indexer  
2 with redis , logstash shipper ans elasticsearch  
So i have 4 instance for ElasticSearch  
I tried to find example of cluster configuraton

and i want to know how to configure logstash output for multiple host  
thank's

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 9, 2015, 8:45am UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194/2 "2015-06-09T08:45:02Z")

</div>

Assuming you mean that you want to connect to multiple hosts for failover and load balancing purposes and only send each message once to each server, just list multiple hosts in the `host` parameter. This requires Logstash 1.5.

```
output {
  elasticsearch {
    host => ["host1", "host2"]
    ...
  }
}

```

If you use the node protocol and multicast this isn't necessary; then Logstash will become a part of the cluster and connect to any node as necessary.

---

<div class="post-metadata">

**Author:** ![saif](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saif/32/37431_2.png) [@saif](https://discuss.elastic.co/u/saif)\
**Post date:** [June 9, 2015, 9:12am UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194/3 "2015-06-09T09:12:26Z")

</div>

thank you  
so its easy to configure cuz im trying to use HAproxy to do that  
ans for the to instance of logstash ?  
logstash dont support fail over like redis ans ES

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 9, 2015, 9:48am UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194/4 "2015-06-09T09:48:05Z")

</div>

Logstash instances are independent from each other. You can use HAproxy, some kind of DNS-based distribution, or native round-robin support (where available; e.g. logstash-forwarder randomly picks one of the IP addresses for A records that resolve to multiple addresses) to distribute the requests.

---

<div class="post-metadata">

**Author:** ![saif](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saif/32/37431_2.png) [@saif](https://discuss.elastic.co/u/saif)\
**Post date:** [June 9, 2015, 11:13am UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194/5 "2015-06-09T11:13:03Z")

</div>

Thank you for this helpful description

---

<div class="post-metadata">

**Author:** ![dkota](https://avatars.discourse-cdn.com/v4/letter/d/46a35a/32.png) [@dkota](https://discuss.elastic.co/u/dkota)\
**Post date:** [March 22, 2016, 12:37pm UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194/6 "2016-03-22T12:37:50Z")

</div>

Can logstash load balance on it's own? I have 3 logstash nodes and 3 Elasticsearch nodes, I want to point all logstash output to cluster and let the logstash decide which node to write on and not have 1:1 mapping with ES.

Is this possible without using a external load balancer?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2016, 12:44pm UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194/7 "2016-03-22T12:44:59Z")

</div>

Quoting the [`hosts` option documentation](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-hosts) for the elasticsearch output in the Logstash 2.2:

> Sets the host(s) of the remote instance. If given an array it will load balance requests across the hosts specified in the hosts parameter.

---

<div class="post-metadata">

**Author:** ![gmmurugan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gmmurugan/32/12488_2.png) [@gmmurugan](https://discuss.elastic.co/u/gmmurugan)\
**Post date:** [October 21, 2016, 7:03pm UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194/8 "2016-10-21T19:03:26Z")

</div>

hosts =\> ["x.x.x.x:9200", "y.y.y.y:9200"]  
is this right ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 23, 2016, 5:09pm UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194/9 "2016-10-23T17:09:56Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:33am UTC](https://discuss.elastic.co/t/logstash-output-for-multiple-elasticsearch-instance/2194/10 "2017-07-06T04:33:09Z")

</div>


