# Logstash to Elasticsearch resilience

**URL:** https://discuss.elastic.co/t/logstash-to-elasticsearch-resilience/301346
**Category:** Elasticsearch
**Created:** [April 1, 2022, 3:15pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-resilience/301346 "2022-04-01T15:15:20Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![gneves](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gneves](https://discuss.elastic.co/u/gneves)
#### Post date: [April 1, 2022, 3:15pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-resilience/301346/1 "2022-04-01T15:15:20Z")

</div>

Hello everyone,

Im having a little bit of trouble finding a way to approach resilience on my Elasticsearch cluster.

Currently i have 2 Logstash nodes for resilience.  
Each one of them are pointing to my 4 Elasticsearch ingest/data\_hot nodes.  
Plus, i have more 3 master nodes coordinating it all.

My problem is, if one of my ingest/data\_nodes fails or go down, Logstash is stopping sending data to elastic giving me the error "Elasticsearch Unreachable: [...] connect timed out"

Is there any way to avoid this errors and keep sending data to the Elasticsearch alive nodes?  
Thank you for your help!!

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [April 1, 2022, 3:21pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-resilience/301346/2 "2022-04-01T15:21:13Z")

</div>

What is your output in logstash pipelines?

Logstash should load balance if you have more than one node in the output configuration, it would give you his error, but would retry to send using another node.

---

<div class="post-metadata">

### Author: ![gneves](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gneves](https://discuss.elastic.co/u/gneves)
#### Post date: [April 1, 2022, 3:30pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-resilience/301346/3 "2022-04-01T15:30:54Z")

</div>

Currently this is the configured logstash output (something like this, edited for privacy):

```auto
elasticsearch {
      hosts => ["https://node1:9200", "https://node2:9200","https://node3:9200","https://node4:9200"]
      index => "filebeat-index-%{+YYYY.ww}"
      pipeline => "filebeat-pipeline"
      user => "logstash"
      password => "${pw}"
      ssl => true
      cacert => "/ca.cer"
      }

```

Currently im also not using replicas, so there are some primary shards missing because of the node that is down.  
In case the logstash keeps indexing when a node is unavailable, maybe thats the reason im not seeing any indexing action?!?

Thank you for your help

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [April 1, 2022, 3:39pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-resilience/301346/4 "2022-04-01T15:39:48Z")

</div>

If there are primary shards missing, then those index will not receive any data until the node with their primary shards are back.

If you want logstash to keep indexing to those index you need to use replicas.

---

<div class="post-metadata">

### Author: ![gneves](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gneves](https://discuss.elastic.co/u/gneves)
#### Post date: [April 1, 2022, 4:33pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-resilience/301346/5 "2022-04-01T16:33:02Z")

</div>

thank you so much for your help.

Gonna implement it.  
Plus, i have another question, is there any way to update the system indices number of replicas?, every one at once. would like to increase them for 3 but i cant find a way to do it!?

I mean, i would like to have 1 replicas of the normal indices, and 3 of the system.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 29, 2022, 4:34pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-resilience/301346/6 "2022-04-29T16:34:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
