# Two Elasticsearch outputs, when one ES cluster has issues Logstash stops shipping to both

**URL:** <https://discuss.elastic.co/t/two-elasticsearch-outputs-when-one-es-cluster-has-issues-logstash-stops-shipping-to-both/147915>\
**Category:** Logstash\
**Created:** [September 10, 2018, 8:16am UTC](https://discuss.elastic.co/t/two-elasticsearch-outputs-when-one-es-cluster-has-issues-logstash-stops-shipping-to-both/147915 "2018-09-10T08:16:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [September 10, 2018, 8:16am UTC](https://discuss.elastic.co/t/two-elasticsearch-outputs-when-one-es-cluster-has-issues-logstash-stops-shipping-to-both/147915/1 "2018-09-10T08:16:28Z")

</div>

Hello all,

I'm working on migrating from Elastic Stack 5.6.X to 6.3.X. So that I would not need to reindex logs from the old cluster tot he new one I thought I would setup a second Elasticsearch output for a few weeks and have the logs go to both clusters for a while before switching log shipping over to go directly to the new cluster.

For some reason log shipping to the new cluster has failed from Logstash a couple of times (still working on finding the root cause). Elasticsearch would just not accept any new logs.

This caused Logstash to ship logs to the old cluster as well which is less than optimal.

**Question** : Is is possible to have more than one _output_ in Logstash and keep sending logs to all healthy outputs even when one output fails?

Any tips welcome 🙂

Cheers,  
AB

---

<div class="post-metadata">

**Author:** ![JPelastic](https://avatars.discourse-cdn.com/v4/letter/j/9e8a1a/32.png) [@JPelastic](https://discuss.elastic.co/u/JPelastic)\
**Post date:** [September 10, 2018, 9:06am UTC](https://discuss.elastic.co/t/two-elasticsearch-outputs-when-one-es-cluster-has-issues-logstash-stops-shipping-to-both/147915/2 "2018-09-10T09:06:57Z")

</div>

I guess you should at least show us your logstash config file. Maybe you have dependencies.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 10, 2018, 9:10am UTC](https://discuss.elastic.co/t/two-elasticsearch-outputs-when-one-es-cluster-has-issues-logstash-stops-shipping-to-both/147915/3 "2018-09-10T09:10:29Z")

</div>

> [@A\_B](#):
>
> **Question** : Is is possible to have more than one _output_ in Logstash and keep sending logs to all healthy outputs even when one output fails?

Not in a single pipeline. Logstash tries to avoid data loss, so will make sure all outputs within a pipeline are successful for a batch before proceeding with the next one.

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [September 10, 2018, 10:21am UTC](https://discuss.elastic.co/t/two-elasticsearch-outputs-when-one-es-cluster-has-issues-logstash-stops-shipping-to-both/147915/4 "2018-09-10T10:21:02Z")

</div>

Thanks @Christian_Dahlqvist

I guess it is this from the documentation

> Having multiple pipelines in a single instance also allows these event flows to have different performance and durability parameters (for example, different settings for pipeline workers and persistent queues). This separation means that a blocked output in one pipeline won’t exert backpressure in the other.

Looks like there are no _pipelines_ in Logstash 5.6.5. Any way to get similar functionality there?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 10, 2018, 10:23am UTC](https://discuss.elastic.co/t/two-elasticsearch-outputs-when-one-es-cluster-has-issues-logstash-stops-shipping-to-both/147915/5 "2018-09-10T10:23:49Z")

</div>

No, not that I am aware of. That would probably require a message queue and multiple Logstash instances pulling separately from this into different clusters.

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [September 10, 2018, 11:52am UTC](https://discuss.elastic.co/t/two-elasticsearch-outputs-when-one-es-cluster-has-issues-logstash-stops-shipping-to-both/147915/6 "2018-09-10T11:52:34Z")

</div>

Ok. Thank you very much for the information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2018, 11:52am UTC](https://discuss.elastic.co/t/two-elasticsearch-outputs-when-one-es-cluster-has-issues-logstash-stops-shipping-to-both/147915/7 "2018-10-08T11:52:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
