# Offline log storage when ingest through elasticsearch/logstash is not avaialble

**URL:** <https://discuss.elastic.co/t/offline-log-storage-when-ingest-through-elasticsearch-logstash-is-not-avaialble/236503>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [June 10, 2020, 11:38am UTC](https://discuss.elastic.co/t/offline-log-storage-when-ingest-through-elasticsearch-logstash-is-not-avaialble/236503 "2020-06-10T11:38:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [June 10, 2020, 11:38am UTC](https://discuss.elastic.co/t/offline-log-storage-when-ingest-through-elasticsearch-logstash-is-not-avaialble/236503/1 "2020-06-10T11:38:45Z")

</div>

Hi, is there a way to configure packetbeat to verify availability of elasticsearch or logstash ingest pipeline on regular basis and if found unavailable store the logs locally, before sending them (again)?

An alternative would be to capture network connection details as part of sysmon and transfer Winlogbeat. However, I was wondering what is the way around for roaming clients who may use split tunnel or direct internet access without being connected to receivers (logstash/elasticsearch). How does beats plan to store logs and send in case ingest is not available?

Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2020, 1:38pm UTC](https://discuss.elastic.co/t/offline-log-storage-when-ingest-through-elasticsearch-logstash-is-not-avaialble/236503/2 "2020-07-08T13:38:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
