# 2 instances of Filebeat on same Linux server output to same ES

**URL:** <https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 28, 2023, 4:13am UTC](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010 "2023-04-28T04:13:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hjazz6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hjazz6/32/79007_2.png) [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Post date:** [April 28, 2023, 4:13am UTC](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010/1 "2023-04-28T04:13:43Z")

</div>

Hi,

I have a Linux server running Filebeat 8.3.3 taking Netflow as input and writing it out to ES on another server. As the Netflow load is much more than what Filebeat can handle, I'm thinking of splitting the Netflow input into 2, i.e. input via 2 physical ports on my Netflow server, then run 2 instances of Filebeat, one for each port, and having both write to the same ES.

Is this feasible? If so, how should I go about configuring it? If not, is there a better way?

Thank you.

---

<div class="post-metadata">

**Author:** ![Dasher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dasher/32/137841_2.png) [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Post date:** [April 28, 2023, 5:12am UTC](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010/2 "2023-04-28T05:12:28Z")

</div>

I think you can configure multiple instances of the filebeat running on different ports and sending data to the same.As for the netflow you can use a load balancer which will distribute the data across these filebeat.  
You can also try optimizing the filebeat

---

<div class="post-metadata">

**Author:** ![hjazz6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hjazz6/32/79007_2.png) [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Post date:** [April 28, 2023, 8:49am UTC](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010/3 "2023-04-28T08:49:27Z")

</div>

When you say "different ports", do you mean different UDP ports in the netflow packets? The packets are all sending to the same UDP port as the port that filebeat is listening on. Is there a way to "tie" different filebeat instances to different physical ports?

Yes, I've also tried to optimize filebeat, and the best I can do thus far is 13K records indexed on ES per second, but that's still not enough to handle the load.

---

<div class="post-metadata">

**Author:** ![Dasher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dasher/32/137841_2.png) [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Post date:** [April 28, 2023, 9:15am UTC](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010/4 "2023-04-28T09:15:09Z")

</div>

Can you try with logstash

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2023, 11:16am UTC](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010/5 "2023-05-26T11:16:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
