# Multiple destinations for failover

**URL:** https://discuss.elastic.co/t/multiple-destinations-for-failover/112188
**Category:** Beats
**Tags:** winlogbeat
**Created:** [December 18, 2017, 9:20am UTC](https://discuss.elastic.co/t/multiple-destinations-for-failover/112188 "2017-12-18T09:20:42Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Mazhar](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@Mazhar](https://discuss.elastic.co/u/Mazhar)
#### Post date: [December 18, 2017, 9:20am UTC](https://discuss.elastic.co/t/multiple-destinations-for-failover/112188/1 "2017-12-18T09:20:42Z")

</div>

## I am configuring the following at my end,

output.kafka:  
enabled:true  
hosts:["kafkahost1:port1","kafkahost2:port2"]

## topic: topic\_name

From the configuration I understand I am sending the same logs/event to multiple receivers, but I am very eager to know how do I configure fail-over destinations. For example if my kafkahost1:port1 is not active, the log/event has to reach kafkahost2:port2.

I did not find much details on the forum, hence adding my points/queries here.

Regards,  
Mazhar

---

<div class="post-metadata">

### Author: ![Mazhar](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@Mazhar](https://discuss.elastic.co/u/Mazhar)
#### Post date: [December 19, 2017, 5:44am UTC](https://discuss.elastic.co/t/multiple-destinations-for-failover/112188/2 "2017-12-19T05:44:41Z")

</div>

@andrewkroh - Can you help me here.

//Mazhar

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [December 19, 2017, 5:50pm UTC](https://discuss.elastic.co/t/multiple-destinations-for-failover/112188/3 "2017-12-19T17:50:46Z")

</div>

`hosts` specifies the addresses of the Kafka brokers where cluster metadata will be fetched. If one is unreachable it will fail-over to the next.

It will use the cluster metadata to determine the partitions for the configured topic. Then will use the metadata to determine the leader for each of the partitions. Then it will start sending data to the host/port associated with the partition leader.

If a partition goes down it can block the output. But you can set reachable\_only: true to have it ignore that partition and move on. See [https://www.elastic.co/guide/en/beats/winlogbeat/current/kafka-output.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/kafka-output.html)

---

<div class="post-metadata">

### Author: ![Mazhar](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@Mazhar](https://discuss.elastic.co/u/Mazhar)
#### Post date: [December 20, 2017, 6:11am UTC](https://discuss.elastic.co/t/multiple-destinations-for-failover/112188/4 "2017-12-20T06:11:21Z")

</div>

Thanks. I am not fully understanding the below parameters, can you put some light on it

topic: '%{[fields.log\_topic]}'  
partition.round\_robin:

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [December 21, 2017, 1:46am UTC](https://discuss.elastic.co/t/multiple-destinations-for-failover/112188/5 "2017-12-21T01:46:28Z")

</div>

> [@Mazhar](#):
>
> topic: '%{[fields.log\_topic]}'

This selects the topic based on the `fields.log_topic` value from the event being published. It allows for the topic to be selected dynamically based on the event contents.

> [@Mazhar](#):
>
> partition.round\_robin:

This is part of the configuration for choosing round robin as the partitioning method. It will send a batch of events to one partition then move on to another partition.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 18, 2018, 1:46am UTC](https://discuss.elastic.co/t/multiple-destinations-for-failover/112188/6 "2018-01-18T01:46:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
