# Which is a better way?

**URL:** <https://discuss.elastic.co/t/which-is-a-better-way/82072>\
**Category:** Elasticsearch\
**Created:** [April 12, 2017, 3:12am UTC](https://discuss.elastic.co/t/which-is-a-better-way/82072 "2017-04-12T03:12:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![danielwalker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielwalker/32/14396_2.png) [@danielwalker](https://discuss.elastic.co/u/danielwalker)\
**Post date:** [April 12, 2017, 3:12am UTC](https://discuss.elastic.co/t/which-is-a-better-way/82072/1 "2017-04-12T03:12:15Z")

</div>

Hi guys,

I am using elasticsearch php-api to write logs directly to Elasticsearch.

There is another way that I put the logs to local machine, then filebeat send logs to logstash, then finally to Elasticsearch.

My colleague said that the latter one is better, since my way goes through the HTTP protocol.

Which is better?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 12, 2017, 3:15am UTC](https://discuss.elastic.co/t/which-is-a-better-way/82072/2 "2017-04-12T03:15:49Z")

</div>

I'd say the second one, because it means you don't have to maintain the code to talk to ES yourself, just write to file.

---

<div class="post-metadata">

**Author:** ![danielwalker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielwalker/32/14396_2.png) [@danielwalker](https://discuss.elastic.co/u/danielwalker)\
**Post date:** [April 12, 2017, 3:18am UTC](https://discuss.elastic.co/t/which-is-a-better-way/82072/3 "2017-04-12T03:18:24Z")

</div>

Yes, apart from the point you mentioned, can I use the first one solution to production?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 12, 2017, 3:19am UTC](https://discuss.elastic.co/t/which-is-a-better-way/82072/4 "2017-04-12T03:19:36Z")

</div>

If you want, sure.

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [April 13, 2017, 2:44pm UTC](https://discuss.elastic.co/t/which-is-a-better-way/82072/5 "2017-04-13T14:44:31Z")

</div>

Two additional points:

1. What happens if Elasticsearch is not reachable from your application? Does it handle that gracefully or does it introduce failures / you need to wait for requests to time out? Degraded logging should probably not impact your production system.

2. Logging to a JSON file and then inserting that directly into Elasticsearch with Filebeat could be a good solution as well. Monolog ([https://github.com/Seldaek/monolog](https://github.com/Seldaek/monolog)) is pretty widely used and can do it. Alternatively it supports Logstash and Elasticsearch outputs directly as well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2017, 2:51pm UTC](https://discuss.elastic.co/t/which-is-a-better-way/82072/6 "2017-05-11T14:51:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
