# Methods to loadbalance on logstash from Input data stream to Filter section

**URL:** <https://discuss.elastic.co/t/methods-to-loadbalance-on-logstash-from-input-data-stream-to-filter-section/271292>\
**Category:** Logstash\
**Created:** [April 26, 2021, 7:14pm UTC](https://discuss.elastic.co/t/methods-to-loadbalance-on-logstash-from-input-data-stream-to-filter-section/271292 "2021-04-26T19:14:50Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 26, 2021, 7:36pm UTC](https://discuss.elastic.co/t/methods-to-loadbalance-on-logstash-from-input-data-stream-to-filter-section/271292/2 "2021-04-26T19:36:54Z")

</div>

This is a really complex question which cannot really be answered in a forum like this. Step one is to identify the bottleneck in the ingestion process. Is it elasticsearch or logstash? Is the process CPU limited? IO limited? If logstash is it the input or the filters in the pipeline that are limiting ingestion?

If the limit is the input then it might help to use multiple inputs, each processing a subset of `*.gz`.

It is certainly possible to configure logstash to divide traffic between other logstash instances. You could use something like

```
filter { ruby { code => 'event.set("[@metadata][target]", rand(3))' } }
output {
    if [@metadata][target] == "0" {
        output { ... }
    } else if [@metadata][target] == "1" {
        output { ... }
    } else {
        output { ... }
    }
}

```

One way of connecting logstash to logstash is described [here](https://www.elastic.co/guide/en/logstash/current/ls-to-ls.html).

---

_[View the full topic](https://discuss.elastic.co/t/methods-to-loadbalance-on-logstash-from-input-data-stream-to-filter-section/271292)._
