# Logstash output to elasticsearch cluster

**URL:** <https://discuss.elastic.co/t/logstash-output-to-elasticsearch-cluster/46742>\
**Category:** Elasticsearch\
**Created:** [April 7, 2016, 8:39pm UTC](https://discuss.elastic.co/t/logstash-output-to-elasticsearch-cluster/46742 "2016-04-07T20:39:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![xo4n](https://avatars.discourse-cdn.com/v4/letter/x/94ad74/32.png) [@xo4n](https://discuss.elastic.co/u/xo4n)\
**Post date:** [April 7, 2016, 8:39pm UTC](https://discuss.elastic.co/t/logstash-output-to-elasticsearch-cluster/46742/1 "2016-04-07T20:39:11Z")

</div>

when ingesting data to an elasticsearch cluster does it bring any advantage configuring logstash to use a client node for load balancing traffic instead of adding the cluster data nodes directly to the output configuration?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 7, 2016, 11:45pm UTC](https://discuss.elastic.co/t/logstash-output-to-elasticsearch-cluster/46742/2 "2016-04-07T23:45:38Z")

</div>

It means you only need to configure LS to talk to localhost, which makes it simple to maintain.

---

<div class="post-metadata">

**Author:** ![xo4n](https://avatars.discourse-cdn.com/v4/letter/x/94ad74/32.png) [@xo4n](https://discuss.elastic.co/u/xo4n)\
**Post date:** [April 8, 2016, 8:32am UTC](https://discuss.elastic.co/t/logstash-output-to-elasticsearch-cluster/46742/3 "2016-04-08T08:32:29Z")

</div>

Actually I dont think it gets simpler as it is an additional component to maintain and monitor in between logstash and elasticsearch, and another potential single point of failure, but I was wondering if on the other hand it would make indexing faster, and if it would add buffering

We are running a client node already with Kibana for load balancing searches to the cluster and we had issues when the cluster is running under heavy load. In such cases the client node will freeze, and kibana will timeout trying to connect to the cluster, when the cluster is back to normal kibana wont be able to connect back because of the client node being irresponsive, only a restart of the client node will make the cluster available for kibana to search again

If the same happens to a client node used by logstash I can imagine that a lot of data could be lost

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 9, 2016, 12:38am UTC](https://discuss.elastic.co/t/logstash-output-to-elasticsearch-cluster/46742/4 "2016-04-09T00:38:43Z")

</div>

Something else is happening then, client nodes will not "freeze".

> [@xo4n](#):
>
> If the same happens to a client node used by logstash I can imagine that a lot of data could be lost

No, because LS puts back pressure back through the pipeline.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:01pm UTC](https://discuss.elastic.co/t/logstash-output-to-elasticsearch-cluster/46742/5 "2017-07-05T23:01:03Z")

</div>


