# Filebeat in HA through active passive

**URL:** https://discuss.elastic.co/t/filebeat-in-ha-through-active-passive/306987
**Category:** Beats
**Tags:** filebeat
**Created:** [June 13, 2022, 5:38am UTC](https://discuss.elastic.co/t/filebeat-in-ha-through-active-passive/306987 "2022-06-13T05:38:39Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![diptesh2007](https://avatars.discourse-cdn.com/v4/letter/d/e79b87/32.png) [@diptesh2007](https://discuss.elastic.co/u/diptesh2007)
#### Post date: [June 13, 2022, 5:38am UTC](https://discuss.elastic.co/t/filebeat-in-ha-through-active-passive/306987/1 "2022-06-13T05:38:39Z")

</div>

I have a requirement to model ELK stack with failover across multiple AWS region.  
While there are no issues with running multiple instances of Logstash and Elasticsearch in active/active mode, the filebeat is expected to ship unique files to logstash from AWS EFS. Hence the filebeat has been modelled as active/passive with **data** folder in AWS EFS and ensuring only 1 instance of filebeat running and shipping files from AWS EFS to logstash.

Is this the right model of filebeat to work or there are other ways to read same file by multiple filebeat process but ensuring only 1 unique file goes to logstash?

---

<div class="post-metadata">

### Author: ![diptesh2007](https://avatars.discourse-cdn.com/v4/letter/d/e79b87/32.png) [@diptesh2007](https://discuss.elastic.co/u/diptesh2007)
#### Post date: [June 22, 2022, 10:05am UTC](https://discuss.elastic.co/t/filebeat-in-ha-through-active-passive/306987/2 "2022-06-22T10:05:42Z")

</div>

Request any advice on this?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [June 22, 2022, 11:56am UTC](https://discuss.elastic.co/t/filebeat-in-ha-through-active-passive/306987/3 "2022-06-22T11:56:42Z")

</div>

> [@diptesh2007](#):
>
> Is this the right model of filebeat to work or there are other ways to read same file by multiple filebeat process but ensuring only 1 unique file goes to logstash?

Filebeat is not clustered so multiple instances are not aware what others are doing/have done. What you are doing therefore as far as I can see seems fine.

---

<div class="post-metadata">

### Author: ![diptesh2007](https://avatars.discourse-cdn.com/v4/letter/d/e79b87/32.png) [@diptesh2007](https://discuss.elastic.co/u/diptesh2007)
#### Post date: [June 23, 2022, 10:18am UTC](https://discuss.elastic.co/t/filebeat-in-ha-through-active-passive/306987/4 "2022-06-23T10:18:14Z")

</div>

Thank you for the response

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 21, 2022, 10:18am UTC](https://discuss.elastic.co/t/filebeat-in-ha-through-active-passive/306987/5 "2022-07-21T10:18:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
