# Multiple filebeat to one logstash. How to optimize the configuration

**URL:** <https://discuss.elastic.co/t/multiple-filebeat-to-one-logstash-how-to-optimize-the-configuration/207045>\
**Category:** Logstash\
**Created:** [November 8, 2019, 5:01am UTC](https://discuss.elastic.co/t/multiple-filebeat-to-one-logstash-how-to-optimize-the-configuration/207045 "2019-11-08T05:01:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [November 8, 2019, 5:01am UTC](https://discuss.elastic.co/t/multiple-filebeat-to-one-logstash-how-to-optimize-the-configuration/207045/1 "2019-11-08T05:01:38Z")

</div>

I have 10 servers that i have Filebeat installed in. Each server monitors 2 applications, a total of 20 applications.

I have one Logstash server which collects all the above logs and passes it to Elasticsearch after filtering of these logs.

To read **one file from one server** , I use the below Logstash configuration:

```auto
input {
  beats {
    port => 5044
  }
}
filter {
    grok {
match => {"message" =>"\[%{TIMESTAMP_ISO8601:timestamp}\]%{SPACE}\[%{DATA:Severity}\]%{SPACE}\[%{DATA:Plugin}\]%{SPACE}\[%{DATA:Servername}\](?<short_message>(.|\r|\n)*)"}
    }
} 
output {
  elasticsearch {
    hosts => ["<ESserverip>:9200"]
    index => "groklogs"
}
          stdout { codec => rubydebug }
}

```

And this is the filebeat configuration:

```auto
paths:
    - D:\ELK 7.1.0\elasticsearch-7.1.0-windows-x86_64\elasticsearch-7.1.0\logs\*.log

output.logstash:
  hosts: ["<logstaship>:5044"]

```

Can anyone please give me an example of

1. How i should convert the above to receive from multiple applications from multiple servers.
2. Should i configure multiple ports? How?
3. How should i use multiple Groks?
4. How can i optimize it in a single or minimal logstash configuration files?

How will a typical set up look. Please help me.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 8, 2019, 3:05pm UTC](https://discuss.elastic.co/t/multiple-filebeat-to-one-logstash-how-to-optimize-the-configuration/207045/2 "2019-11-08T15:05:52Z")

</div>

> [@katara](#):
>
> How i should convert the above to receive from multiple applications from multiple servers.

Why can't you process input from multiple servers and applications with the existing configuration?

---

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [November 8, 2019, 3:24pm UTC](https://discuss.elastic.co/t/multiple-filebeat-to-one-logstash-how-to-optimize-the-configuration/207045/3 "2019-11-08T15:24:57Z")

</div>

@Badger because different application logs are involved in different servers.  
I mean, will it work if I write multiple grok statements for collecting from all the logs? How would I differenciate the application details if the logs don't give any?  
And can I map all filebeat to reach a single port 5044?  
Even if I have more than one path in each server?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 8, 2019, 3:47pm UTC](https://discuss.elastic.co/t/multiple-filebeat-to-one-logstash-how-to-optimize-the-configuration/207045/4 "2019-11-08T15:47:56Z")

</div>

You can add tags to each prospector in filebeat, then use conditionals based on the tags to determine which filters to apply.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2019, 3:47pm UTC](https://discuss.elastic.co/t/multiple-filebeat-to-one-logstash-how-to-optimize-the-configuration/207045/5 "2019-12-06T15:47:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
