# Rsyslogd replaces with Logstash and/or Filebeat?

**URL:** <https://discuss.elastic.co/t/rsyslogd-replaces-with-logstash-and-or-filebeat/173660>\
**Category:** Logstash\
**Created:** [March 25, 2019, 3:04am UTC](https://discuss.elastic.co/t/rsyslogd-replaces-with-logstash-and-or-filebeat/173660 "2019-03-25T03:04:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasony](https://avatars.discourse-cdn.com/v4/letter/j/a3d4f5/32.png) [@jasony](https://discuss.elastic.co/u/jasony)\
**Post date:** [March 25, 2019, 3:04am UTC](https://discuss.elastic.co/t/rsyslogd-replaces-with-logstash-and-or-filebeat/173660/1 "2019-03-25T03:04:34Z")

</div>

hello,

I am managing one cluster and current service-flow is as below.

**SYSLOG** -\> **Rsyslogd** (store data into disk) -\> **Logstash** (read from disk and transfer to Kafka) -\> **Kafka** -\> **Logstash** -\> **Elasticsearch**

Problem is current Rsyslogd is not really stable, and I would replace with Logstash or Filebeat.

**Option#1:**

If i will go with Logstash, service-flow will be like below.

**SYSLOG** -\> **Logstash** (directly transfer to Kafka, then store into disk as backup) -\> **Kafka** -\> **Logstash** -\> **Elasticsearch**

**Option#2:**

If i will go with Filebeat, service-flow will be like below.

**SYSLOG** -\> **Filebeat** (store data into disk) -\> **Logstash** (read from disk and transfer to Kafka) -\> **Kafka** -\> **Logstash** -\> **Elasticsearch**  
OR  
**SYSLOG** -\> **Filebeat** (directly transfer to Logstash) -\> **Logstash** (transfer to Kafka) -\> **Kafka** -\> **Logstash** -\> **Elasticsearch**

Can you please advise which option is better and what i need to consider more for stability?

Thank you!

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [March 28, 2019, 11:12pm UTC](https://discuss.elastic.co/t/rsyslogd-replaces-with-logstash-and-or-filebeat/173660/2 "2019-03-28T23:12:43Z")

</div>

I find it weird that you say rsyslogd is unstable. Usually when it's configured properly it's stable and does what you tell it. You say little about your environment, so it's hard to make a qualified response. What load do you have (msg/sec). What kind of network design? How many servers.. etc etc. To minimize disk IO you might wanna look at having rsyslogd forward directly to logstash instead of having logstash read from files. Then you can keep logstash at one server, and just use rsyslogd to forward msgs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2019, 11:20pm UTC](https://discuss.elastic.co/t/rsyslogd-replaces-with-logstash-and-or-filebeat/173660/3 "2019-04-25T23:20:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
