# Multiple logstash forwarder instances

**URL:** <https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850>\
**Category:** Logstash\
**Created:** [September 23, 2015, 4:11pm UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850 "2015-09-23T16:11:47Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![paulkeogh](https://avatars.discourse-cdn.com/v4/letter/p/8dc957/32.png) [@paulkeogh](https://discuss.elastic.co/u/paulkeogh)\
**Post date:** [September 23, 2015, 4:11pm UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/1 "2015-09-23T16:11:47Z")

</div>

Hi,

I am running multiple LF instances on a single host - unfortunately I started them both from the same working directory so they are sharing a .logstash-forwarder file.

I presume this is incorrect and I will rectify it - but could this error give rise to duplicate events that I subsequently see in Elasticsearch ?

Thanks,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 23, 2015, 5:17pm UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/2 "2015-09-23T17:17:51Z")

</div>

Are both instance reading from the same file? If so then yes, it could definitely lead to duplicate events.

---

<div class="post-metadata">

**Author:** ![paulkeogh](https://avatars.discourse-cdn.com/v4/letter/p/8dc957/32.png) [@paulkeogh](https://discuss.elastic.co/u/paulkeogh)\
**Post date:** [September 24, 2015, 8:17am UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/3 "2015-09-24T08:17:12Z")

</div>

Hi,

Thanks for your reply.

No, both instances are reading files from separate directions but they are sharing the same .logstash-forwarder file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 24, 2015, 8:22am UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/4 "2015-09-24T08:22:40Z")

</div>

Hmm. That probably results in them periodically trampling on each other's .logstash-forwarder files, so if you restart both then one of them is going to lose its state. You should grab a copy of the file, shut down the instance that created the file, shut down the other one after you've made that it has flushed its internal state and overwritten the state file, then restart the LSF instances from different directories to which you've moved each instance's state file.

---

<div class="post-metadata">

**Author:** ![paulkeogh](https://avatars.discourse-cdn.com/v4/letter/p/8dc957/32.png) [@paulkeogh](https://discuss.elastic.co/u/paulkeogh)\
**Post date:** [September 24, 2015, 11:47am UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/5 "2015-09-24T11:47:36Z")

</div>

Thank you again for your reply. I have refactored my scripts to ensure that each LF instance now starts in a unique working directory.

BTW, I also found a workaround for this issue by using the logstash fingerprint filter to get a hash of the message and then using the fingerprint value as a document\_id when submitting the document to elasticsearch. This ensures no exact duplicates make it into elasticsearch.

---

<div class="post-metadata">

**Author:** ![Yarden\_Bar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yarden_bar/32/736_2.png) [@Yarden\_Bar](https://discuss.elastic.co/u/Yarden_Bar)\
**Post date:** [November 4, 2015, 10:35am UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/6 "2015-11-04T10:35:18Z")

</div>

Hi Magnus,  
Can you ellaborate on how to do so?  
In my use-case, LSF is installed from rpm to `/opt/logstash-forwarder` and is started with init script (`/etc/init.d/logstash-forwarder`)

I don't understand how shall I start it...

Thank you,  
Yarden

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 4, 2015, 1:16pm UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/7 "2015-11-04T13:16:20Z")

</div>

> Can you ellaborate on how to do so?

Do what? Did you also manage to start two instances of LSF from the same directory?

---

<div class="post-metadata">

**Author:** ![Yarden\_Bar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yarden_bar/32/736_2.png) [@Yarden\_Bar](https://discuss.elastic.co/u/Yarden_Bar)\
**Post date:** [November 4, 2015, 2:53pm UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/8 "2015-11-04T14:53:57Z")

</div>

Yes, but I suspect they clash because they both use `/var/lib/logstash-forwarder/.logstash-forwarder` as a state file.

> [@magnusbaeck](#):
>
> then restart the LSF instances from different directories to which you've moved each instance's state file.

I understand that I should stop using LSF init script and run it from different directories? this means that the state file gets created in the directory I'm running the command from?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 4, 2015, 2:56pm UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/9 "2015-11-04T14:56:10Z")

</div>

Yes, LSF creates the state file in the current directory. That doesn't mean that you need to stop using the init script, but you may have to modify it.

---

<div class="post-metadata">

**Author:** ![Yarden\_Bar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yarden_bar/32/736_2.png) [@Yarden\_Bar](https://discuss.elastic.co/u/Yarden_Bar)\
**Post date:** [November 5, 2015, 6:51am UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/10 "2015-11-05T06:51:56Z")

</div>

I've modified the init script to reflect the second LSF.  
Also modified /etc/default/logstash-forwarder-OTHER file, configured 'chdir' to a different directory.

Should I expect to see the **second** LSF state file in 'chdir' directory?

I'm using `lsof` to determine which state file each LSF processes is using.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 5, 2015, 7:27am UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/11 "2015-11-05T07:27:17Z")

</div>

If you succeed in changing the starting directory of the LSF process then that's where you'll find the state file.

---

<div class="post-metadata">

**Author:** ![Yarden\_Bar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yarden_bar/32/736_2.png) [@Yarden\_Bar](https://discuss.elastic.co/u/Yarden_Bar)\
**Post date:** [November 5, 2015, 7:42am UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/12 "2015-11-05T07:42:53Z")

</div>

I think that I've manage to change the starting directory:

```
sudo pwdx 30315 # LSF-OTHER PID
30315: /var/lib/logstash-forwarder-OTHER

```

But I don't see the state file there:

```
ls -la /var/lib/logstash-forwarder-OTHER
total 8
drwxrwxr-x 2 logstash-forwarder logstash-forwarder 4096 Nov 4 08:03 .
drwxr-xr-x 27 root root 4096 Nov 4 08:03 ..

```

The server is "Scientific Linux release 6.1 (Carbon)"  
Also, nothing in the logs to indicate problem with opening/creating the state file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:23am UTC](https://discuss.elastic.co/t/multiple-logstash-forwarder-instances/29850/13 "2017-07-06T05:23:56Z")

</div>


