# Filebeat output to multiple ElasticSearch

**URL:** <https://discuss.elastic.co/t/filebeat-output-to-multiple-elasticsearch/177131>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 16, 2019, 5:28pm UTC](https://discuss.elastic.co/t/filebeat-output-to-multiple-elasticsearch/177131 "2019-04-16T17:28:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![algilber](https://avatars.discourse-cdn.com/v4/letter/a/ebca7d/32.png) [@algilber](https://discuss.elastic.co/u/algilber)\
**Post date:** [April 16, 2019, 5:28pm UTC](https://discuss.elastic.co/t/filebeat-output-to-multiple-elasticsearch/177131/1 "2019-04-16T17:28:26Z")

</div>

Hi,  
I have a server RHEL7 with filebeat client installed. I want to send the syslog to a cluster of ElasticSearch (elk01) and the logs of Nginx to another one (elk02). What's the config for that. The first one wotk great. But I don't know how to configure the module for Nginx.

* * *

- module: nginx  
setup.kibana.host: ["elk02:5601"]  
output.elasticsearch.hosts: ["elk02:2900"]

* * *

Thanks !

---

<div class="post-metadata">

**Author:** ![Ryne\_Keel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryne_keel/32/42827_2.png) [@Ryne\_Keel](https://discuss.elastic.co/u/Ryne_Keel)\
**Post date:** [April 16, 2019, 5:49pm UTC](https://discuss.elastic.co/t/filebeat-output-to-multiple-elasticsearch/177131/2 "2019-04-16T17:49:38Z")

</div>

It sounds like you have two different clusters? If so, then I would try to find a post about running multiple filebeats from the same directory. Basically then you just start filebeat twice and point each one to a different config file.

So you would have something like syslog.yml and nginx.yml inside of the filebeat directory, and then in the modules .yml files just specify the access and error logs part like you already did, but put the kibana.host and elasticsearch.hosts settings inside of the configuration files in the filebeat directory

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2019, 5:49pm UTC](https://discuss.elastic.co/t/filebeat-output-to-multiple-elasticsearch/177131/3 "2019-05-14T17:49:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
