# Filebeat agent configuration for two different endpoint(logstash ,kafka clusters)

**URL:** https://discuss.elastic.co/t/filebeat-agent-configuration-for-two-different-endpoint-logstash-kafka-clusters/168863
**Category:** Logstash
**Created:** [February 18, 2019, 3:44pm UTC](https://discuss.elastic.co/t/filebeat-agent-configuration-for-two-different-endpoint-logstash-kafka-clusters/168863 "2019-02-18T15:44:29Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![msina](https://avatars.discourse-cdn.com/v4/letter/m/a698b9/32.png) [@msina](https://discuss.elastic.co/u/msina)
#### Post date: [February 18, 2019, 3:44pm UTC](https://discuss.elastic.co/t/filebeat-agent-configuration-for-two-different-endpoint-logstash-kafka-clusters/168863/1 "2019-02-18T15:44:30Z")

</div>

Hi,

I have one apache HTTPD server and filebeat is already installed there and sending few specific logs to our internal **logstatsh server**.  
currently it is sending logs to our internal logstash server are  
/var/log/httpd/access\_log  
/var/log/httpd/error\_log  
/var/log/httpd/dispatcher.log

output.logstash:  
hosts: ["internal.logstasht:5044"]  
bulk\_max\_size: 1024  
username: "abc"  
password: "xyz"

Now we have requirement to send few other logs from the system to our IT security department in their specific **kafka clsuters**.

"/var/log/audit\*"  
"/var/log/secure\*"  
'/etc/ssh/sshd\_config  
/var/log/httpd/access\_log (common need to send both logstash and kafka cluster)  
/var/log/httpd/error\_log (commons need to send both logstash and kafaka cluster)

output.kafka:  
hosts: ["184.XXX.XX.XX:9093", "184.XXX.XX.XX:9093"]  
username: "xyz"  
password: "abc"  
compression: snappy  
topic: '%{[topic]}'

Can anyone please suggest how can i achieve this.

---

<div class="post-metadata">

### Author: ![danhermann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danhermann/32/33024_2.png) [@danhermann](https://discuss.elastic.co/u/danhermann)
#### Post date: [February 20, 2019, 9:09pm UTC](https://discuss.elastic.co/t/filebeat-agent-configuration-for-two-different-endpoint-logstash-kafka-clusters/168863/2 "2019-02-20T21:09:20Z")

</div>

@msina, this is really a Beats question rather than a Logstash question and would probably be better asked in that forum. That said, you can run two separate instances of Filebeat on your server, each with a separate output, because Beats do not support multiple outputs.

---

<div class="post-metadata">

### Author: ![msina](https://avatars.discourse-cdn.com/v4/letter/m/a698b9/32.png) [@msina](https://discuss.elastic.co/u/msina)
#### Post date: [February 21, 2019, 4:09pm UTC](https://discuss.elastic.co/t/filebeat-agent-configuration-for-two-different-endpoint-logstash-kafka-clusters/168863/3 "2019-02-21T16:09:53Z")

</div>

@danhermann Actually i already got the solution here

> [@How to install and configure multiple filebeat in linux instance](https://discuss.elastic.co/t/how-to-install-and-configure-multiple-filebeat-in-linux-instance/130466):
>
> I have already installed one filebeat and it is working fine. I need to create multiple filebeat in the linux instances. How to start and stop the filebeat if we install multiple filebeat instances? How to differentiate the registry file? Want to use the same index for the multiple instances? Can you please help me with this? This is bit urgent.

Thanks  
Sina

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 21, 2019, 4:10pm UTC](https://discuss.elastic.co/t/filebeat-agent-configuration-for-two-different-endpoint-logstash-kafka-clusters/168863/4 "2019-03-21T16:10:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
