# LogStash sends data directly to ES bypassing Graylog2 server?

**URL:** <https://discuss.elastic.co/t/logstash-sends-data-directly-to-es-bypassing-graylog2-server/12227>\
**Category:** Elasticsearch\
**Created:** [June 2, 2013, 6:47pm UTC](https://discuss.elastic.co/t/logstash-sends-data-directly-to-es-bypassing-graylog2-server/12227 "2013-06-02T18:47:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kaush777](https://avatars.discourse-cdn.com/v4/letter/k/43a26b/32.png) [@kaush777](https://discuss.elastic.co/u/kaush777)\
**Post date:** [June 2, 2013, 6:47pm UTC](https://discuss.elastic.co/t/logstash-sends-data-directly-to-es-bypassing-graylog2-server/12227/1 "2013-06-02T18:47:37Z")

</div>

Hi All,

I ran a crash test on the LogStash +Redis + Graylog + ES ecosystem and am  
a bit confused. I have a setup in which logstash agents send data to Redis  
Db, after which it goes to a central logstash instance and then to ES via  
Graylog.  
So, I first killed the central logstash instance, so the data began to  
accumulate in Redis. Then, I brought it up, but killed Graylog server. But  
even then I observed that the data in Redis DB was emptied without any  
problems! I know that my central logstash instance sends data in GELF to  
ES, but it does so via Graylog server right? So if the Graylog server was  
off, how was it able to connect to ES? I did netstat for port 12201, but it  
didnt throw up any results. So how and where was the data emptied? If there  
is no one listening at 12201, where did the Logstash send the data from  
Redis to?? Or am I going wrong somewhere?  
Because we say to Logstash in its conf files that :

output  
{  
gelf {host =\> a.b.c.d} and the port is 12201 by default.  
So here the host is where the Graylog server is listening on 12201 right?  
If so, how come was the Graylog server off, no one listening on 12201 and  
the data was transferred?

I know that ES is the message store for Graylog, but shouldn't the graylog  
server be up for it to function ?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Edward\_Sargisson](https://avatars.discourse-cdn.com/v4/letter/e/b4bc9f/32.png) [@Edward\_Sargisson](https://discuss.elastic.co/u/Edward_Sargisson)\
**Post date:** [June 3, 2013, 3:31pm UTC](https://discuss.elastic.co/t/logstash-sends-data-directly-to-es-bypassing-graylog2-server/12227/2 "2013-06-03T15:31:39Z")

</div>

Why do you have a Graylog server in there at all?  
Logstash certainly can write directly to ES - and is probably what you want  
so that Kibana can read it.  
If you really want Graylog working then have a look at the output  
configuration of your logstash server and make sure that it is actually  
going ot Graylog.

Cheers,  
Edward

On Sunday, June 2, 2013 11:47:37 AM UTC-7, Kaushal wrote:

> Hi All,
> 
> I ran a crash test on the LogStash +Redis + Graylog + ES ecosystem and am  
> a bit confused. I have a setup in which logstash agents send data to Redis  
> Db, after which it goes to a central logstash instance and then to ES via  
> Graylog.  
> So, I first killed the central logstash instance, so the data began to  
> accumulate in Redis. Then, I brought it up, but killed Graylog server. But  
> even then I observed that the data in Redis DB was emptied without any  
> problems! I know that my central logstash instance sends data in GELF to  
> ES, but it does so via Graylog server right? So if the Graylog server was  
> off, how was it able to connect to ES? I did netstat for port 12201, but it  
> didnt throw up any results. So how and where was the data emptied? If there  
> is no one listening at 12201, where did the Logstash send the data from  
> Redis to?? Or am I going wrong somewhere?  
> Because we say to Logstash in its conf files that :
> 
> output  
> {  
> gelf {host =\> a.b.c.d} and the port is 12201 by default.  
> So here the host is where the Graylog server is listening on 12201 right?  
> If so, how come was the Graylog server off, no one listening on 12201 and  
> the data was transferred?
> 
> I know that ES is the message store for Graylog, but shouldn't the graylog  
> server be up for it to function ?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:33am UTC](https://discuss.elastic.co/t/logstash-sends-data-directly-to-es-bypassing-graylog2-server/12227/3 "2017-07-06T02:33:17Z")

</div>


