# Filebeat shared or per application server

**URL:** <https://discuss.elastic.co/t/filebeat-shared-or-per-application-server/219412>\
**Category:** Beats\
**Created:** [February 14, 2020, 4:17pm UTC](https://discuss.elastic.co/t/filebeat-shared-or-per-application-server/219412 "2020-02-14T16:17:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![areller](https://avatars.discourse-cdn.com/v4/letter/a/e480ec/32.png) [@areller](https://discuss.elastic.co/u/areller)\
**Post date:** [February 14, 2020, 4:17pm UTC](https://discuss.elastic.co/t/filebeat-shared-or-per-application-server/219412/1 "2020-02-14T16:17:05Z")

</div>

We have a .NET Framework stack where each application instance is deployed on its own windows server.

We want to move to ELK instead of just writing log files to a shared network drive.

What would be the best solution in your opinion? Having a single (or a set number) of filebeat instances in a Linux server that read logs from the share network drive (or mount to the windows server drives)?

Or having a Filebeat for every windows server that hosts an instance of the application, and sending it to a shared Logstash?

Would the latter pose any performance concerns?

Thank you.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [February 14, 2020, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-shared-or-per-application-server/219412/2 "2020-02-14T16:31:16Z")

</div>

Avoid reading logs from a network share, run filebeat on each server and have applications log to local disk.

---

<div class="post-metadata">

**Author:** ![areller](https://avatars.discourse-cdn.com/v4/letter/a/e480ec/32.png) [@areller](https://discuss.elastic.co/u/areller)\
**Post date:** [February 14, 2020, 4:48pm UTC](https://discuss.elastic.co/t/filebeat-shared-or-per-application-server/219412/3 "2020-02-14T16:48:57Z")

</div>

Thank you for replying.  
Could there be other solutions where I would have filebeat instances on separate server but just not use network drive, but instead do something else like mount the windows drive on the filebeat server?

Or is having filebeat per application server is the best solution overall?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [February 14, 2020, 4:54pm UTC](https://discuss.elastic.co/t/filebeat-shared-or-per-application-server/219412/4 "2020-02-14T16:54:40Z")

</div>

I would avoid anything using the word "mount" 🙂

Simple filebeat configurations don't seem to use a lot of resource per instance, they might use more depending on what all is done in modules and things I haven't used yet. We using filebeat to harvest logs from exchange servers without problems and there are a LOT of events.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2020, 6:54pm UTC](https://discuss.elastic.co/t/filebeat-shared-or-per-application-server/219412/5 "2020-03-13T18:54:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
