# Deploy & Monitor Filebeat

**URL:** <https://discuss.elastic.co/t/deploy-monitor-filebeat/80791>\
**Category:** Beats\
**Created:** [March 31, 2017, 9:30am UTC](https://discuss.elastic.co/t/deploy-monitor-filebeat/80791 "2017-03-31T09:30:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndreAga](https://avatars.discourse-cdn.com/v4/letter/a/ed8c4c/32.png) [@AndreAga](https://discuss.elastic.co/u/AndreAga)\
**Post date:** [March 31, 2017, 9:30am UTC](https://discuss.elastic.co/t/deploy-monitor-filebeat/80791/1 "2017-03-31T09:30:21Z")

</div>

Hi all,  
the question is very simple, is there a way to deploy/install Filebeat in thousand (25.000/50.000) of machines?  
Solutions like puppet, ansible, chef or Docker are very expensive. Maybe with few machines the cost is reasonable, but when the number grows, the cost is disproportionate.

Another question, can I use heartbeat to check the status of Filebeat?

Thank you.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 31, 2017, 2:14pm UTC](https://discuss.elastic.co/t/deploy-monitor-filebeat/80791/2 "2017-03-31T14:14:52Z")

</div>

What is the tool you use to manage these 50k machines? Can you also share some info on why puppet etc. get very expensive?

For the monitoring best have a look at [https://github.com/elastic/beats/issues/3422](https://github.com/elastic/beats/issues/3422). Currently with heartbeat monitoring is not possible. Potentially this PR could make it possible but as I don't recommend the port to the outside, you would need heartbeat in addition on each node. [https://github.com/elastic/beats/pull/3717](https://github.com/elastic/beats/pull/3717)

---

<div class="post-metadata">

**Author:** ![AndreAga](https://avatars.discourse-cdn.com/v4/letter/a/ed8c4c/32.png) [@AndreAga](https://discuss.elastic.co/u/AndreAga)\
**Post date:** [March 31, 2017, 2:33pm UTC](https://discuss.elastic.co/t/deploy-monitor-filebeat/80791/3 "2017-03-31T14:33:28Z")

</div>

Puppet, etc. are expensive because the license is (generally) based on the number of "managed" nodes and here the number is a bit high. On the other hand, Chef for example requires an agent installed on each machine and this is not so elengant.

Currently I don't use any kind of tool, I have only to propose a solution for this problem and eventually use it. But I think it's not so easy.

> [@ruflin](#):
>
> For the monitoring best have a look at [Beats central monitoring Phase 1 · Issue #3422 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/3422). Currently with heartbeat monitoring is not possible. Potentially this PR could make it possible but as I don't recommend the port to the outside, you would need heartbeat in addition on each node. [https://github.com/elastic/beats/pull/3717](https://github.com/elastic/beats/pull/3717)

Thanks.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [April 3, 2017, 6:33am UTC](https://discuss.elastic.co/t/deploy-monitor-filebeat/80791/4 "2017-04-03T06:33:10Z")

</div>

I thought you mean "expensive" from a resource specific point of view and was not thinking of the commercial part of puppet 🙂 I have to feeling if you have that many machines you will not some sort of automation tool anyways. As soon as you decided for one, filebeat can be handled very similar to all the other applications you will install.

---

<div class="post-metadata">

**Author:** ![AndreAga](https://avatars.discourse-cdn.com/v4/letter/a/ed8c4c/32.png) [@AndreAga](https://discuss.elastic.co/u/AndreAga)\
**Post date:** [April 3, 2017, 7:53am UTC](https://discuss.elastic.co/t/deploy-monitor-filebeat/80791/5 "2017-04-03T07:53:08Z")

</div>

Thank you Ruflin 🙂  
But, any plan to integrate this kind of feature in the next versions of Beats? Maybe in the "central configuration management" (What’s brewin’ in Beats, Elastic{on} '17)?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [April 3, 2017, 7:59pm UTC](https://discuss.elastic.co/t/deploy-monitor-filebeat/80791/6 "2017-04-03T19:59:22Z")

</div>

The monitoring part is definitively on our agenda. So far we don't have any concrete plans to also have a way to update and ship a binary as this would require to be already on the nodes. And for this tool you would probably need again some automation ...

---

<div class="post-metadata">

**Author:** ![AndreAga](https://avatars.discourse-cdn.com/v4/letter/a/ed8c4c/32.png) [@AndreAga](https://discuss.elastic.co/u/AndreAga)\
**Post date:** [April 3, 2017, 8:46pm UTC](https://discuss.elastic.co/t/deploy-monitor-filebeat/80791/7 "2017-04-03T20:46:26Z")

</div>

Think about that 🙂 because a way to distribute (and update) the Beats (or Elastic stack) components via SSH, maybe with a standalone app, would be the killer feature and it would make really full the stack.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2017, 9:30am UTC](https://discuss.elastic.co/t/deploy-monitor-filebeat/80791/8 "2017-04-21T09:30:23Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
