# Detect when the setup command was already executed on a machine

**URL:** <https://discuss.elastic.co/t/detect-when-the-setup-command-was-already-executed-on-a-machine/288983>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 11, 2021, 10:48am UTC](https://discuss.elastic.co/t/detect-when-the-setup-command-was-already-executed-on-a-machine/288983 "2021-11-11T10:48:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![VirtualEvan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/virtualevan/32/97008_2.png) [@VirtualEvan](https://discuss.elastic.co/u/VirtualEvan)\
**Post date:** [November 11, 2021, 10:48am UTC](https://discuss.elastic.co/t/detect-when-the-setup-command-was-already-executed-on-a-machine/288983/1 "2021-11-11T10:48:12Z")

</div>

Hi there. I am working on some PowerShell DSC configurations which include installation and setup of Filebeat.  
In general everything works fine, but I am struggling to find a way to detect if the setup command was already executed on the machine. This is important to DSC so it can know whether the machine is actually in the desired state or not.  
I would like to avoid creating a dummy file for detection, so I was wondering if there was some command or maybe an API call to detect if a node id/hostname has been already set up.

I am quite new to everything related to ElasticStack, so this might come from not completely getting all the concepts of what the setup command does.

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [November 11, 2021, 5:49pm UTC](https://discuss.elastic.co/t/detect-when-the-setup-command-was-already-executed-on-a-machine/288983/2 "2021-11-11T17:49:10Z")

</div>

With setup would you mean like the "filebeat setup" command or just the installation of filebeat?

The first one is only needed to be run once anywhere, and is not required to be run on each host, as the setup command simply prepares Elasticsearch and kibana with its relevant resources.

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [November 11, 2021, 5:52pm UTC](https://discuss.elastic.co/t/detect-when-the-setup-command-was-already-executed-on-a-machine/288983/3 "2021-11-11T17:52:12Z")

</div>

On another note, if you want to just confirm filebeat is working as intended, and you didn't mean the above setup command, you can run "filebeat test output", which tries to ping the configured Elasticsearch output.

---

<div class="post-metadata">

**Author:** ![VirtualEvan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/virtualevan/32/97008_2.png) [@VirtualEvan](https://discuss.elastic.co/u/VirtualEvan)\
**Post date:** [November 12, 2021, 9:18am UTC](https://discuss.elastic.co/t/detect-when-the-setup-command-was-already-executed-on-a-machine/288983/4 "2021-11-12T09:18:32Z")

</div>

Yes, I was referring to the `filebeat setup` command.  
My understanding was that it had to be done once per host. It is clear now that running it in only one host will be enough.

However, I face the same situation for the host which will run the command.  
Is there a way of checking if these relevant resources already exist? Let's say another filebeat command/flag or an API call to Elasticsearch?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 10, 2021, 11:19am UTC](https://discuss.elastic.co/t/detect-when-the-setup-command-was-already-executed-on-a-machine/288983/5 "2021-12-10T11:19:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
