# 2 instance filebeat reading the same file

**URL:** <https://discuss.elastic.co/t/2-instance-filebeat-reading-the-same-file/243704>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 4, 2020, 12:24pm UTC](https://discuss.elastic.co/t/2-instance-filebeat-reading-the-same-file/243704 "2020-08-04T12:24:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![zeO](https://avatars.discourse-cdn.com/v4/letter/z/e95f7d/32.png) [@zeO](https://discuss.elastic.co/u/zeO)\
**Post date:** [August 4, 2020, 12:24pm UTC](https://discuss.elastic.co/t/2-instance-filebeat-reading-the-same-file/243704/1 "2020-08-04T12:24:39Z")

</div>

Hi, I am using Elastic Kibana and filebeat to read and monitor my docker container (docker stack) logs. for compagnie policy reason I need to send the logs at 2 elasticsearch locations (the project instance and the compagnie standard instance).

I read that filebeat allow only one output. So here is my question, is it possible to run 2 filebeats instances on the same server reading the same log files but with 2 differents output ?

thank you for your time and anwser 🙂

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [August 4, 2020, 12:44pm UTC](https://discuss.elastic.co/t/2-instance-filebeat-reading-the-same-file/243704/2 "2020-08-04T12:44:49Z")

</div>

It is possible, but you cannot use the provided packages. You'll have to build from source and make sure you have separate data, config and service.

---

<div class="post-metadata">

**Author:** ![zeO](https://avatars.discourse-cdn.com/v4/letter/z/e95f7d/32.png) [@zeO](https://discuss.elastic.co/u/zeO)\
**Post date:** [August 4, 2020, 1:21pm UTC](https://discuss.elastic.co/t/2-instance-filebeat-reading-the-same-file/243704/3 "2020-08-04T13:21:37Z")

</div>

thx i'll try that

---

<div class="post-metadata">

**Author:** ![tjfred](https://avatars.discourse-cdn.com/v4/letter/t/e9c0ed/32.png) [@tjfred](https://discuss.elastic.co/u/tjfred)\
**Post date:** [August 4, 2020, 3:07pm UTC](https://discuss.elastic.co/t/2-instance-filebeat-reading-the-same-file/243704/4 "2020-08-04T15:07:42Z")

</div>

I'm running multiple filebeats on the same host using debian packages:

create the extra data dir:  
`mkdir /var/lib/filebeat-other`

create the extra log dir:  
`mkdir /var/log/filebeat-other`

copy the systemd service file:  
`cp /usr/lib/systemd/system/filebeat.service /usr/lib/systemd/system/filebeat-other.service`

copy the filebeat config file:  
`cp /etc/filebeat/filebeat.yml /etc/filebeat/filebeat-other.yml`

edit the systemd service file:  
`sed -i 's/filebeat.yml/filebeat-other.yml/' /usr/lib/systemd/system/filebeat-other.service`  
`sed -i 's/lib\/filebeat/lib\/filebeat-other/' /usr/lib/systemd/system/filebeat-other.service`  
`sed -i 's/log\/filebeat/log\/filebeat-other/' /usr/lib/systemd/system/filebeat-other.service`

reload systemd config:  
`systemctl daemon-reload`

enable new service:  
`systemctl enable filebeat-other`

start new service:  
`systemctl start filebeat-other`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2020, 5:07pm UTC](https://discuss.elastic.co/t/2-instance-filebeat-reading-the-same-file/243704/5 "2020-09-01T17:07:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
