# Shipping and indexing

**URL:** <https://discuss.elastic.co/t/shipping-and-indexing/63161>\
**Category:** Logstash\
**Created:** [October 17, 2016, 7:48am UTC](https://discuss.elastic.co/t/shipping-and-indexing/63161 "2016-10-17T07:48:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![laywin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laywin/32/14059_2.png) [@laywin](https://discuss.elastic.co/u/laywin)\
**Post date:** [October 17, 2016, 7:48am UTC](https://discuss.elastic.co/t/shipping-and-indexing/63161/1 "2016-10-17T07:48:04Z")

</div>

i read the reference [https://www.elastic.co/guide/en/logstash/current/deploying-and-scaling.html](https://www.elastic.co/guide/en/logstash/current/deploying-and-scaling.html),  
in the article,shipping logstash collect logs first then logs pass messge queue finally indexing logstash filter logs.  
in our situation,we have many apps on different machines,we need to collect logs apps produced, our solution is that first we use logstash to filter logs then pass message queue finally use logstash ship logs to es. i think this solution can balance logstash filter pressure on machines and better than first ship then filter. is that right?thanks in advance!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 17, 2016, 7:57am UTC](https://discuss.elastic.co/t/shipping-and-indexing/63161/2 "2016-10-17T07:57:17Z")

</div>

Please format your post, it is impossible to read.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 19, 2016, 5:49am UTC](https://discuss.elastic.co/t/shipping-and-indexing/63161/3 "2016-10-19T05:49:14Z")

</div>

Why would it be easier to load balance _before_ the message broker? Half the point of using a message broker is the ease with which one can balance the load.

The other main point is that you want to get your logs away from your critical path as soon as possible, and using the message broker as a buffer before the filters makes good sense since the first Logstash instance can accept messages at a high rate.

---

<div class="post-metadata">

**Author:** ![laywin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laywin/32/14059_2.png) [@laywin](https://discuss.elastic.co/u/laywin)\
**Post date:** [October 19, 2016, 6:56am UTC](https://discuss.elastic.co/t/shipping-and-indexing/63161/4 "2016-10-19T06:56:19Z")

</div>

thanks you answer!

because indexing logstash could consume more resources than shipping logstash,our applications deploy on different server,if i first index then ship,the indexing pressure can balance on different server,on the contrast,there would be more pressure on indexing logstash ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 19, 2016, 6:58am UTC](https://discuss.elastic.co/t/shipping-and-indexing/63161/5 "2016-10-19T06:58:48Z")

</div>

Okay, I see what you mean. It makes sense if you don't mind running a potentially expensive Logstash process on each server and if you're not interested in central filtering. I prefer lightweight shippers and centralized filtering.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:33am UTC](https://discuss.elastic.co/t/shipping-and-indexing/63161/6 "2017-07-06T04:33:37Z")

</div>


