It doesn't matter where the logstash servers are, if they are sending to an elastic store that is full, they can't log. They might have persistent queues and could temporarily hold some data, but diagnosing broken systems beyond the obvious break is "an exercise left to the reader" :-}
Just to make sure, disks at logstash:5044 are full, disks at localhost:5044 aren't but still localhost:5044 refuses to log / refuses to receive messages / does not get messages from Winlogbeat... I assumed that this is what a cluster is for, if one node fails others take over.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.