# How to get filebeat to output to ES multiple servers

**URL:** <https://discuss.elastic.co/t/how-to-get-filebeat-to-output-to-es-multiple-servers/78835>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 16, 2017, 10:29am UTC](https://discuss.elastic.co/t/how-to-get-filebeat-to-output-to-es-multiple-servers/78835 "2017-03-16T10:29:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![eddie4](https://avatars.discourse-cdn.com/v4/letter/e/838e76/32.png) [@eddie4](https://discuss.elastic.co/u/eddie4)\
**Post date:** [March 16, 2017, 10:29am UTC](https://discuss.elastic.co/t/how-to-get-filebeat-to-output-to-es-multiple-servers/78835/1 "2017-03-16T10:29:41Z")

</div>

Hello everyone,

Am using the filebeat for Suricata & ES server. Now my colleague have decided to use filebeat as well. But they are using a completely different setup. I have been attempting to set different configurations in conf.d. However it won't accept multiple output servers as far as i can see.

My question:  
What would be the best way to configure filebeat to read two different logs and output to two different servers?

---

<div class="post-metadata">

**Author:** ![giuseppe](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@giuseppe](https://discuss.elastic.co/u/giuseppe)\
**Post date:** [March 16, 2017, 5:06pm UTC](https://discuss.elastic.co/t/how-to-get-filebeat-to-output-to-es-multiple-servers/78835/2 "2017-03-16T17:06:52Z")

</div>

Hi Eddie,

You can find info on how to configure multiple logs here:

[https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html)

For the ES output you can use the `hosts` option, which is a list of strings:

[https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#hosts-option](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#hosts-option)

---

<div class="post-metadata">

**Author:** ![eddie4](https://avatars.discourse-cdn.com/v4/letter/e/838e76/32.png) [@eddie4](https://discuss.elastic.co/u/eddie4)\
**Post date:** [March 17, 2017, 2:19pm UTC](https://discuss.elastic.co/t/how-to-get-filebeat-to-output-to-es-multiple-servers/78835/3 "2017-03-17T14:19:07Z")

</div>

Thanks for you response but perhaps I wasn't clear enough.

Server1 has apache and suricata logs.

Apache logs need to end up on logstash\_server\_1 and there after ES\_server 1  
Suricata logs need to end up on logstash\_server\_2 and there after ES\_server 2

The options for multiple servers is for cluster servers. But in this case the servers are not in a cluster. And data needs to remain separate.

---

<div class="post-metadata">

**Author:** ![Jayanna\_Hallur](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@Jayanna\_Hallur](https://discuss.elastic.co/u/Jayanna_Hallur)\
**Post date:** [March 17, 2017, 4:02pm UTC](https://discuss.elastic.co/t/how-to-get-filebeat-to-output-to-es-multiple-servers/78835/4 "2017-03-17T16:02:06Z")

</div>

I think you can use 2 config files and run seperate filebeat instances for each config file..

one filebeat instance will be started with the config file having Apache logs need to end up on logstash\_server\_1 and there after ES\_server 1

and second filebeat instance will be started with the config file having Suricata logs need to end up on logstash\_server\_2 and there after ES\_server 2

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2017, 4:02pm UTC](https://discuss.elastic.co/t/how-to-get-filebeat-to-output-to-es-multiple-servers/78835/5 "2017-04-14T16:02:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
