# Filebeat and Okta System Logs HA scenario

**URL:** https://discuss.elastic.co/t/filebeat-and-okta-system-logs-ha-scenario/352012
**Category:** Beats
**Tags:** filebeat
**Created:** [January 29, 2024, 3:19pm UTC](https://discuss.elastic.co/t/filebeat-and-okta-system-logs-ha-scenario/352012 "2024-01-29T15:19:48Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![g.vecchi](https://avatars.discourse-cdn.com/v4/letter/g/958977/32.png) [@g.vecchi](https://discuss.elastic.co/u/g.vecchi)
#### Post date: [January 29, 2024, 3:19pm UTC](https://discuss.elastic.co/t/filebeat-and-okta-system-logs-ha-scenario/352012/1 "2024-01-29T15:19:48Z")

</div>

Hi guys,

I need to send Okta System Logs to our Elastic Cloud tenant and I'm looking for a scenario that satisfies active-active or active-passive high availability configuration.  
In case of the active-active one, 2 concurrent filebeat instances will run in 2 different AWS AZs as per AWS Best Practices, but I don't know if this is a valid scenario as per as the Okta integration works.  
In case of the active-passive one, how can I make the passive start where the active finished so as to avoid duplication?  
Any useful idea will be appreciated.

Thanks

---

<div class="post-metadata">

### Author: ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)
#### Post date: [January 31, 2024, 5:23pm UTC](https://discuss.elastic.co/t/filebeat-and-okta-system-logs-ha-scenario/352012/2 "2024-01-31T17:23:47Z")

</div>

Hi,

it's only an idea, so to avoid duplication, you can use the `filebeat.registry.path` configuration option. This option specifies the location where Filebeat keeps its registry file, which is used to track the last read offset. By storing this file on a shared filesystem accessible from both AZs, you can ensure that both Filebeat instances start reading from where the other one left off.

Regards

---

<div class="post-metadata">

### Author: ![g.vecchi](https://avatars.discourse-cdn.com/v4/letter/g/958977/32.png) [@g.vecchi](https://discuss.elastic.co/u/g.vecchi)
#### Post date: [February 2, 2024, 4:16pm UTC](https://discuss.elastic.co/t/filebeat-and-okta-system-logs-ha-scenario/352012/3 "2024-02-02T16:16:06Z")

</div>

Dear @yago82

your idea is the best workaround I found until now, thanks man.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 1, 2024, 6:16pm UTC](https://discuss.elastic.co/t/filebeat-and-okta-system-logs-ha-scenario/352012/4 "2024-03-01T18:16:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
