Where Does Logstash Store Pipelines and Queues?
Logstash pipeline configs and disk queue folder paths on Linux for Elastic log shippers. Plus migration notes.
Last updated
Logstash keeps pipelines in /etc/logstash/conf.d as .conf files. Each file chains inputs, filters, and outputs. The main logstash.yml beside them sets workers and queue paths.
Persistent queues live in /var/lib/logstash/queue when enabled. Those buffer events during Elasticsearch outages. Back up configs with the queue folder. Queues drain on restart, configs persist behavior. Grok patterns parse unstructured lines. Beats inputs accept Filebeat traffic by default. Dead letter queues catch failures.
Where Logstash stores this, by platform
/etc/logstash/conf.d
Pipeline .conf files with inputs and outputs. Test with configtest flag before reloading. Keep in version control for team review.
/var/lib/logstash/queue
Persistent event queues for outage buffering. Enabled per pipeline in settings. Copy with Logstash stopped for consistency.
Frequently asked questions
what do i back up for a Logstash move
Copy /etc/logstash with /var/lib/logstash for queue recovery. Configs hold inputs and outputs. Queues buffer events to Elasticsearch. Both restore processing.
where are Logstash pipeline configs
Look in /etc/logstash/conf.d with .conf files per pipeline. The main logstash.yml sets paths and workers. Test changes with logstash --config.test_and_exit first.
Notice an outdated path? Let us know.