# Filebeat on ECK reading multiple copies

**URL:** https://discuss.elastic.co/t/filebeat-on-eck-reading-multiple-copies/361815
**Category:** Beats
**Tags:** filebeat
**Created:** [June 21, 2024, 3:31am UTC](https://discuss.elastic.co/t/filebeat-on-eck-reading-multiple-copies/361815 "2024-06-21T03:31:00Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Varun\_Tokas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varun_tokas/32/124452_2.png) [@Varun\_Tokas](https://discuss.elastic.co/u/Varun_Tokas)
#### Post date: [June 21, 2024, 3:31am UTC](https://discuss.elastic.co/t/filebeat-on-eck-reading-multiple-copies/361815/1 "2024-06-21T03:31:01Z")

</div>

I have ECK deployed on a cluster with 10 nodes. There is a large file which I want uploaded to Elasticsearch, and the file is stored on a network drive mounted onto each machine, meaning that each node can access the file at the same path. When I use Filebeat, what ends up happening is that since one instance runs on every machine, each instance sends the same data to the same index since they share the configuration. How can I tell filebeat to read the file from only one instance? Any advice would be appreciated.

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [June 21, 2024, 3:57am UTC](https://discuss.elastic.co/t/filebeat-on-eck-reading-multiple-copies/361815/2 "2024-06-21T03:57:35Z")

</div>

> [@Varun\_Tokas](#):
>
> How can I tell filebeat to read the file from only one instance?

I don't think you can, if you have multiple filebeats reading the same file, you will get duplicates.

In this case you need to have just one filebeat reading from that file.

---

<div class="post-metadata">

### Author: ![Varun\_Tokas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varun_tokas/32/124452_2.png) [@Varun\_Tokas](https://discuss.elastic.co/u/Varun_Tokas)
#### Post date: [June 21, 2024, 3:58am UTC](https://discuss.elastic.co/t/filebeat-on-eck-reading-multiple-copies/361815/3 "2024-06-21T03:58:14Z")

</div>

But this means I cannot run Filebeat as a DaemonSet on Kubernetes, right? Since all the created instances in that case would have the exact same configuration, and hence read the same file

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [June 21, 2024, 4:06am UTC](https://discuss.elastic.co/t/filebeat-on-eck-reading-multiple-copies/361815/4 "2024-06-21T04:06:03Z")

</div>

I do not use Kubernetes, but as mentioned you need to have just one instance of Filebeat reading from that file.

Can you not configure the DaemonSet to run just on one node? From this [example](https://kubernetes.io/docs/tasks/manage-daemon/pods-some-nodes/) it seems to be possible to do something like that.
