# Multiple Filebeat configurations on different servers sending to 1 logstash

**URL:** https://discuss.elastic.co/t/multiple-filebeat-configurations-on-different-servers-sending-to-1-logstash/191265
**Category:** Logstash
**Created:** [July 18, 2019, 6:20pm UTC](https://discuss.elastic.co/t/multiple-filebeat-configurations-on-different-servers-sending-to-1-logstash/191265 "2019-07-18T18:20:48Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)
#### Post date: [July 18, 2019, 6:20pm UTC](https://discuss.elastic.co/t/multiple-filebeat-configurations-on-different-servers-sending-to-1-logstash/191265/1 "2019-07-18T18:20:48Z")

</div>

It is my understanding that Logstash can handle multiple instances of filebeat. My question is whether there is a pro to configuring multiple Logstash instances to handle 3-4 filebeat instances (all on different servers).

Also, for now I have one filebeat instance sending to logstash on a different server. If I were to add another filebeat instance, would I need to restart logstash for it to recognize a new filebeat input?

Thanks in advance.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 18, 2019, 6:22pm UTC](https://discuss.elastic.co/t/multiple-filebeat-configurations-on-different-servers-sending-to-1-logstash/191265/2 "2019-07-18T18:22:47Z")

</div>

I don't think the number of filebeat instances is a reason to add logstash instances unless the logstash instance is falling behind.

> [@userR](#):
>
> If I were to add another filebeat instance, would I need to restart logstash for it to recognize a new filebeat input?

No, logstash will accept input from any server that connects to the port it is listening on.

---

<div class="post-metadata">

### Author: ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)
#### Post date: [July 18, 2019, 6:43pm UTC](https://discuss.elastic.co/t/multiple-filebeat-configurations-on-different-servers-sending-to-1-logstash/191265/3 "2019-07-18T18:43:17Z")

</div>

Quick follow up:

For now I have one grok pattern specified for one filebeat instance. If I add another filebeat instance, I plan on adding a different grok filter.

So I will need to be modifying my configuration file (using if/else statements depending on log\_type specified in filebeat.yml files). In that case, I assume I will have to restart the logstash instance right?  
And if so, when I run the logstash instance again, filebeat will be able to correctly recognize where it left off (even with rotating logs)?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 18, 2019, 6:56pm UTC](https://discuss.elastic.co/t/multiple-filebeat-configurations-on-different-servers-sending-to-1-logstash/191265/4 "2019-07-18T18:56:56Z")

</div>

You do not need to restart, you can use SIGHUP to tell logstash to re-read the configuration, or enable --config.reload.automatic so that logstash polls to see if the configuration has changed. I do not think you will lose data when that happens but I am not absolutely certain.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 15, 2019, 6:57pm UTC](https://discuss.elastic.co/t/multiple-filebeat-configurations-on-different-servers-sending-to-1-logstash/191265/5 "2019-08-15T18:57:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
