# POSTFIX Ingest and the future of Logstash

**URL:** https://discuss.elastic.co/t/postfix-ingest-and-the-future-of-logstash/390279
**Category:** Elastic Agent
**Created:** [September 9, 2026, 12:32pm UTC](https://discuss.elastic.co/t/postfix-ingest-and-the-future-of-logstash/390279 "2026-09-09T12:32:16Z")
**Posts on this page:** 1
**Showing post:** 5

<div class="post-metadata">

### Author: ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)
#### Post date: [September 10, 2026, 12:32pm UTC](https://discuss.elastic.co/t/postfix-ingest-and-the-future-of-logstash/390279/5 "2026-09-10T12:32:33Z")

</div>

Your first post had:

> [@RalphDibney](#):
>
> our MSP that helps us with it has a logstash based integration that is also merges the mutliline log of postfix to one document.

Now, thats a black box to me, but someone somewhere has created that integration. How it works, what it really does, what the end result looks like is not given. But the implication is that it's "good enough", right ?

If I were you, knowing what I know now, I'd not try to re-invent the wheel and use what I understand is a supported (by your MSP) working setup. I don't see great advantage of say developing/testing/supporting something with an Agent or other tool to do same job as the one you already have. If the only fear is "Logstash _might_ be retired in X months/years", then for me that risk does not outweigh the advantages.

btw there was a thread [long ago](https://discuss.elastic.co/t/filebeat-multiline-by-queue-id/47406) on postfix logs and correlating on queueID, and this [blog](https://blog.veroone.fr/posts/001_postfix-aggregation-logstash/) entry covers much the same territory.

---

_[View the full topic](https://discuss.elastic.co/t/postfix-ingest-and-the-future-of-logstash/390279)._
