# Rsyslog.conf configured for more then 1 elasticsearch server?

**URL:** <https://discuss.elastic.co/t/rsyslog-conf-configured-for-more-then-1-elasticsearch-server/37835>\
**Category:** Elasticsearch\
**Created:** [December 23, 2015, 9:10am UTC](https://discuss.elastic.co/t/rsyslog-conf-configured-for-more-then-1-elasticsearch-server/37835 "2015-12-23T09:10:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![smm](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@smm](https://discuss.elastic.co/u/smm)\
**Post date:** [December 23, 2015, 9:10am UTC](https://discuss.elastic.co/t/rsyslog-conf-configured-for-more-then-1-elasticsearch-server/37835/1 "2015-12-23T09:10:48Z")

</div>

Dear community,  
I would like to use **rsyslod-Daemon** to send logs to our elasticsearch **cluster**. As you konw there is an output module for elasticsearch you can use. Prior to that you have to configure it. My question relates to the configuration: Can I say in that module to send to more than one elasticsearch node in a cluster? In my config below I tell rsyslog to send to 1 machine (one node of that cluster), but could I also give a list of nodes hoping rsyslog (in a round robin mode) sends the log to one of the cluster nodes instead of only one?

Thank you for your insights!!!!

**# vim /etc/rsyslog.conf**  
...  
module(load="omelasticsearch")  
template(name="testTemplate"  
type="list"  
option.json="on") {  
constant(value="{")  
constant(value=""timestamp":"") property(name="timereported" dateFormat="rfc3339")  
constant(value="","message":"") property(name="msg")  
constant(value="","host":"") property(name="hostname")  
constant(value="","severity":"") property(name="syslogseverity-text")  
constant(value="","facility":"") property(name="syslogfacility-text")  
constant(value="","syslogtag":"") property(name="syslogtag")  
constant(value=""}")  
}  
action(type="omelasticsearch"  
server="ubuntu64"  
serverport="9200"  
template="testTemplate"  
searchIndex="test-index"  
searchType="test-type"  
bulkmode="on"  
queue.type="linkedlist"  
queue.size="5000"  
queue.dequeuebatchsize="300"  
action.resumeretrycount="-1")  
...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 23, 2015, 10:00pm UTC](https://discuss.elastic.co/t/rsyslog-conf-configured-for-more-then-1-elasticsearch-server/37835/2 "2015-12-23T22:00:36Z")

</div>

> [@smm](#):
>
> Can I say in that module to send to more than one elasticsearch node in a cluster?

That might be better off asked on an rsyslog forum, however perhaps someone else has experience with this and can help 🙂

---

<div class="post-metadata">

**Author:** ![LordTamo](https://avatars.discourse-cdn.com/v4/letter/l/b782af/32.png) [@LordTamo](https://discuss.elastic.co/u/LordTamo)\
**Post date:** [April 21, 2016, 3:07pm UTC](https://discuss.elastic.co/t/rsyslog-conf-configured-for-more-then-1-elasticsearch-server/37835/3 "2016-04-21T15:07:42Z")

</div>

Hi, this works for me :

ruleset(name="rule\_1")  
{action(type="mmutf8fix" mode="controlcharacters")  
action(type="omelasticsearch" server="192.168.aa.aa" serverport="9200" template="tpl\_host-ip" searchIndex="index-name" bulkmode="off" dynSearchIndex="on")  
& action(type="omelasticsearch" server="[192.168.bb.bb](http://192.168.bb.bb)" serverport="9200" template="tpl\_host-ip" searchIndex="index-name" bulkmode="off" dynSearchIndex="on" action.execOnlyWhenPreviousIsSuspended="on")

"action.execOnlyWhenPreviousIsSuspended" tell to rsyslog to use this action in case of problem with the previous. don't forget the '&' before the 'action'

Bastien

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:57pm UTC](https://discuss.elastic.co/t/rsyslog-conf-configured-for-more-then-1-elasticsearch-server/37835/4 "2017-07-05T22:57:15Z")

</div>


