# Best practices for multiple instances of file beat vs. one filebeat instance with multiple prospectors

**URL:** <https://discuss.elastic.co/t/best-practices-for-multiple-instances-of-file-beat-vs-one-filebeat-instance-with-multiple-prospectors/170043>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 26, 2019, 4:16pm UTC](https://discuss.elastic.co/t/best-practices-for-multiple-instances-of-file-beat-vs-one-filebeat-instance-with-multiple-prospectors/170043 "2019-02-26T16:16:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![roblopes](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@roblopes](https://discuss.elastic.co/u/roblopes)\
**Post date:** [February 26, 2019, 4:16pm UTC](https://discuss.elastic.co/t/best-practices-for-multiple-instances-of-file-beat-vs-one-filebeat-instance-with-multiple-prospectors/170043/1 "2019-02-26T16:16:18Z")

</div>

Hi,

I am replacing an existing enterprise logging system by Elastic Stack. I have hundreds of applications currently using the current system. Those applications they are spread across 3 or 4 servers (depending on the environment).

I am planning to use a filebeat forwarding the logs to two logstash instances, that will take care of parsing the logs (grok) and forwarding the log to Elasticsearch.

What would be the best practice in this case, one filebeat with multiple prospectors, or multiple filebeat with one prospector each?

If not enough information, please let me know.

Appreciate your input.

Thanks,  
Rob

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [February 27, 2019, 4:48am UTC](https://discuss.elastic.co/t/best-practices-for-multiple-instances-of-file-beat-vs-one-filebeat-instance-with-multiple-prospectors/170043/2 "2019-02-27T04:48:42Z")

</div>

Hi Rob,

In my experience, one FileBeat instance per server is more than sufficient. We are using FileBeat on our central logging server with **multiple prospectors** and we have touch an **EPS of 20,000** from a single instance, even after multi line conversions. (It could go even higher, but Logstash cannot handle it on the current hardware! 😃 )

So, if you have a distributed environment, I don't see a need to have more than one FileBeat instance on a server. Multiple prospectors should be the way to go, if you want to capture logs from 20-30 paths. Should be done easily.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [February 27, 2019, 8:32am UTC](https://discuss.elastic.co/t/best-practices-for-multiple-instances-of-file-beat-vs-one-filebeat-instance-with-multiple-prospectors/170043/3 "2019-02-27T08:32:04Z")

</div>

I agree with @NerdSec  
I also suggest you take a look at Filebeat modules if you are open to eliminating Logstash from the infrastructure and sending events directly Elasticsearch: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-overview.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-overview.html)

---

<div class="post-metadata">

**Author:** ![roblopes](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@roblopes](https://discuss.elastic.co/u/roblopes)\
**Post date:** [February 27, 2019, 1:51pm UTC](https://discuss.elastic.co/t/best-practices-for-multiple-instances-of-file-beat-vs-one-filebeat-instance-with-multiple-prospectors/170043/4 "2019-02-27T13:51:28Z")

</div>

Hi,

Thanks a lot for your response. I really appreciate. It's good to know that FileBeat can hold such high volume.

Cheers,  
Rob

---

<div class="post-metadata">

**Author:** ![roblopes](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@roblopes](https://discuss.elastic.co/u/roblopes)\
**Post date:** [February 27, 2019, 1:52pm UTC](https://discuss.elastic.co/t/best-practices-for-multiple-instances-of-file-beat-vs-one-filebeat-instance-with-multiple-prospectors/170043/5 "2019-02-27T13:52:53Z")

</div>

@kvch,

Thanks for your input. I'll take a look at the filebeat modules.

Cheers,  
Rob

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2019, 1:52pm UTC](https://discuss.elastic.co/t/best-practices-for-multiple-instances-of-file-beat-vs-one-filebeat-instance-with-multiple-prospectors/170043/6 "2019-03-27T13:52:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
