# Writing to multiple Elasticsearch Nodes

**URL:** https://discuss.elastic.co/t/writing-to-multiple-elasticsearch-nodes/68553
**Category:** Logstash
**Created:** [December 9, 2016, 11:34am UTC](https://discuss.elastic.co/t/writing-to-multiple-elasticsearch-nodes/68553 "2016-12-09T11:34:52Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![tomx1](https://avatars.discourse-cdn.com/v4/letter/t/779978/32.png) [@tomx1](https://discuss.elastic.co/u/tomx1)
#### Post date: [December 9, 2016, 11:34am UTC](https://discuss.elastic.co/t/writing-to-multiple-elasticsearch-nodes/68553/1 "2016-12-09T11:34:52Z")

</div>

I was just reading this article: [https://www.elastic.co/guide/en/logstash/current/deploying-and-scaling.html](https://www.elastic.co/guide/en/logstash/current/deploying-and-scaling.html)

I'm wondering how writing to multiple Elasticsearch nodes works in Logstash. In particular, let's assume I am shipping log events out of an single Logstash instance to 3 ELS Nodes. Like shown in the images here:  
[https://www.elastic.co/guide/en/logstash/current/static/images/deploy\_4.png](https://www.elastic.co/guide/en/logstash/current/static/images/deploy_4.png)

What happens, if one of those ELS nodes becomes unavailable? Is logstash trying it again on the same node or does it "hand over" the event to the next available node?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [December 10, 2016, 10:09pm UTC](https://discuss.elastic.co/t/writing-to-multiple-elasticsearch-nodes/68553/2 "2016-12-10T22:09:37Z")

</div>

A node that isn't available will be marked as "bad" for a while and Logstash will send requests to the remaining nodes.

---

<div class="post-metadata">

### Author: ![tomx1](https://avatars.discourse-cdn.com/v4/letter/t/779978/32.png) [@tomx1](https://discuss.elastic.co/u/tomx1)
#### Post date: [December 12, 2016, 7:54am UTC](https://discuss.elastic.co/t/writing-to-multiple-elasticsearch-nodes/68553/3 "2016-12-12T07:54:43Z")

</div>

Thanks Magnus, good to know... maybe you also know what is happening to the single event which is the first one to fail on a specific node. Is this single event lost?

Is there a documentation about the mechanism on how the elasticsearch output plugin marks nodes as bad. I'm interested to know how long a node is marked as bad until the output plugin is trying it again and so on...

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 9, 2017, 7:54am UTC](https://discuss.elastic.co/t/writing-to-multiple-elasticsearch-nodes/68553/4 "2017-01-09T07:54:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
