# Prevent data loss if elasticsearch not available

**URL:** <https://discuss.elastic.co/t/prevent-data-loss-if-elasticsearch-not-available/358624>\
**Category:** Logstash\
**Created:** [May 2, 2024, 9:33am UTC](https://discuss.elastic.co/t/prevent-data-loss-if-elasticsearch-not-available/358624 "2024-05-02T09:33:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Frances\_Chu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frances_chu/32/127298_2.png) [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Post date:** [May 2, 2024, 9:33am UTC](https://discuss.elastic.co/t/prevent-data-loss-if-elasticsearch-not-available/358624/1 "2024-05-02T09:33:57Z")

</div>

If data send from filebeat to logstash then Elasticsearch.

How to prevent data loss if

case 1. Logstash not available  
case 2 elasticsearch not available

any special configuration can be performed in both filebeat and logstash?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 2, 2024, 5:18pm UTC](https://discuss.elastic.co/t/prevent-data-loss-if-elasticsearch-not-available/358624/2 "2024-05-02T17:18:55Z")

</div>

I cannot speak to filebeat, but logstash has an at-least-once delivery model. If elasticsearch is down it will stop processing events when the queues fill up, and tell filebeat to stop sending it data.

---

<div class="post-metadata">

**Author:** ![Frances\_Chu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frances_chu/32/127298_2.png) [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Post date:** [May 3, 2024, 7:31am UTC](https://discuss.elastic.co/t/prevent-data-loss-if-elasticsearch-not-available/358624/3 "2024-05-03T07:31:20Z")

</div>

Big thx
