# How to configure Elastic Agent to stream different data to different instances of ElasticSearch?

**URL:** <https://discuss.elastic.co/t/how-to-configure-elastic-agent-to-stream-different-data-to-different-instances-of-elasticsearch/368691>\
**Category:** Beats\
**Tags:** elastic-agent\
**Created:** [October 11, 2024, 2:43pm UTC](https://discuss.elastic.co/t/how-to-configure-elastic-agent-to-stream-different-data-to-different-instances-of-elasticsearch/368691 "2024-10-11T14:43:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![starstone](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@starstone](https://discuss.elastic.co/u/starstone)\
**Post date:** [October 11, 2024, 2:43pm UTC](https://discuss.elastic.co/t/how-to-configure-elastic-agent-to-stream-different-data-to-different-instances-of-elasticsearch/368691/1 "2024-10-11T14:43:36Z")

</div>

Hi

How do you configure Elastic Agent to stream security logs to a dedicated instance of Elasticsearch and other data to a different instance of ElsticSearch? I want two segregated instances of Elasticsearch: one dedicated to support SIEM functionality; second to support obervability/enterprise system performance monitoring. I want to avoid performance monitoring impacting the operational performance of the SIEM functionality.

Thanks.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 11, 2024, 2:56pm UTC](https://discuss.elastic.co/t/how-to-configure-elastic-agent-to-stream-different-data-to-different-instances-of-elasticsearch/368691/2 "2024-10-11T14:56:50Z")

</div>

From #Elastic Search to #Beats

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 11, 2024, 2:56pm UTC](https://discuss.elastic.co/t/how-to-configure-elastic-agent-to-stream-different-data-to-different-instances-of-elasticsearch/368691/3 "2024-10-11T14:56:51Z")

</div>

Added #elastic-agent

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 12, 2024, 5:31am UTC](https://discuss.elastic.co/t/how-to-configure-elastic-agent-to-stream-different-data-to-different-instances-of-elasticsearch/368691/4 "2024-10-12T05:31:34Z")

</div>

Hi @starstone

Today (8.15.2), Elastic Agent can only ship telemetry to a single output per Agent / Fleet Policy, even when the policy has multiple integrations. That is an Elastic Agent limitation.

However if you look/follow this issue you will you will see that the feature for defining and output per integration well under development. You can follow this. We do not announce future feature release dates on this discuss forum.

> <https://github.com/elastic/kibana/issues/143905>
>
> There are many legitimate reasons why an operator may need/want to send data fro…m integrations to different outputs within a policy. Some may even need to send datastream to different outputs. Currently we only allow an output to be defined on a per policy basis. In order to support this request the per policy output definition needs to be over-written by the output defined in the integration. Our config should support this already.
> 
> \*\*Use Cases:\*\*
> 
> 1) As an operator, I need my security logs from an agent to be sent to one logstash where as informational logs to be sent to another logstash instance.
> 
> 2) We operate multiple beats on a given system and would like to migrate to using Elastic Agent. For historical and operational reasons these beats are writing data to distinct outputs. Once we migrate over to using Agent, we would like to keep the upstream pipeline intact.

You can also create an architecture like

Elastic Agent -\> Logstash -\> To Many Elasticsearch Clusters

---

<div class="post-metadata">

**Author:** ![starstone](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@starstone](https://discuss.elastic.co/u/starstone)\
**Post date:** [October 14, 2024, 8:45am UTC](https://discuss.elastic.co/t/how-to-configure-elastic-agent-to-stream-different-data-to-different-instances-of-elasticsearch/368691/5 "2024-10-14T08:45:41Z")

</div>

@stephenb Thanks for the advice. I get it. I look forward to the release of the new enhancement.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2024, 8:46am UTC](https://discuss.elastic.co/t/how-to-configure-elastic-agent-to-stream-different-data-to-different-instances-of-elasticsearch/368691/6 "2024-11-11T08:46:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
