# Should A Full DLQ Queue Effect Logstash Performance Signifigantly?

**URL:** <https://discuss.elastic.co/t/should-a-full-dlq-queue-effect-logstash-performance-signifigantly/271036>\
**Category:** Logstash\
**Created:** [April 23, 2021, 5:01am UTC](https://discuss.elastic.co/t/should-a-full-dlq-queue-effect-logstash-performance-signifigantly/271036 "2021-04-23T05:01:38Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 23, 2021, 2:33pm UTC](https://discuss.elastic.co/t/should-a-full-dlq-queue-effect-logstash-performance-signifigantly/271036/5 "2021-04-23T14:33:26Z")

</div>

> [@scott\_stash](#):
>
> If I don’t configure DLQ my Logstash pipeline will keep sending the event to ES infinitely.. and ES will keep responding with a 400 series error.

When an event is sent to an elasticsearch there are two status codes returned, and the retry handling for them is different.

If the \_bulk request returns an error, unless it is a 429 it is [retried indefinitely](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/e4f220951215d1a79a2b6224a365a58b1a059ccb/lib/logstash/plugin_mixins/elasticsearch/common.rb#L311). In some cases this makes no sense (e.g. a 413 error will always recur if retried and thus it will shut down the flow of events).

Each request within the \_bulk payload also returns a status. For these, if the code is 400 or 404 then the [event is sent to the DLQ if configured](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/e4f220951215d1a79a2b6224a365a58b1a059ccb/lib/logstash/plugin_mixins/elasticsearch/common.rb#L262), otherwise, if a 409 it is dropped, otherwise it is retried indefinitely (or "for everything else there is Mastercard" as the comment says).

logstash has an at-least-once delivery model, so it leans towards retries. The documentation says "If the DLQ is not enabled, and a mapping error happens, the problem is logged as a warning, and the event is dropped". That is specific to 409 errors, everything else is retried indefinitely.

---

_[View the full topic](https://discuss.elastic.co/t/should-a-full-dlq-queue-effect-logstash-performance-signifigantly/271036)._
