# Mutiple filebeat servers to Single logstash server

**URL:** <https://discuss.elastic.co/t/mutiple-filebeat-servers-to-single-logstash-server/214725>\
**Category:** Logstash\
**Created:** [January 12, 2020, 11:53am UTC](https://discuss.elastic.co/t/mutiple-filebeat-servers-to-single-logstash-server/214725 "2020-01-12T11:53:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pathfinder225](https://avatars.discourse-cdn.com/v4/letter/p/bbe5ce/32.png) [@pathfinder225](https://discuss.elastic.co/u/pathfinder225)\
**Post date:** [January 12, 2020, 11:53am UTC](https://discuss.elastic.co/t/mutiple-filebeat-servers-to-single-logstash-server/214725/1 "2020-01-12T11:53:36Z")

</div>

Hi,  
New to ELK and I am doing a production setup . I have 3 servers and installed filebeat on each of them.  
now i am sending these 3 filebeat inputs to single logstash using below config.

In all 3 servers Filebeat output is configured as :

type: log  
enabled: true  
paths:  
- /wls\_domains/Microservices/logs/app/\*.log

logstash output to x.x.x.x:5044

x.x.x.x is ip of logstash server

logstash config:

input {  
beats {  
port =\> 5044  
}  
}

output {  
elasticsearch {  
hosts =\> ["[http://host](http://host):port"]  
index =\> "service-%{+YYYY.MM.dd}"  
#user =\> "elastic"  
#password =\> "changeme"  
}  
stdout { codec =\> rubydebug }  
}

The problem now is my logstash can listen to beat on one server at any time,. logs sent by filebeat from all 3 servers are not read simultaneously by logstash.

can you please help here!

Thank you!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 12, 2020, 3:05pm UTC](https://discuss.elastic.co/t/mutiple-filebeat-servers-to-single-logstash-server/214725/2 "2020-01-12T15:05:52Z")

</div>

> [@pathfinder225](#):
>
> The problem now is my logstash can listen to beat on one server at any time,. logs sent by filebeat from all 3 servers are not read simultaneously by logstash.

I would expect logstash to read events from any number of beats that write to port 5044, not just one. I do not run filebeat so I cannot help with debugging the issue.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 12, 2020, 4:19pm UTC](https://discuss.elastic.co/t/mutiple-filebeat-servers-to-single-logstash-server/214725/3 "2020-01-12T16:19:34Z")

</div>

I agree, that config should read from any number of filebeat senders. If this is your logstash config, your problem is elsewhere.

Do you eventually get events from all 3 filebeat servers, just delayed?

---

<div class="post-metadata">

**Author:** ![pathfinder225](https://avatars.discourse-cdn.com/v4/letter/p/bbe5ce/32.png) [@pathfinder225](https://discuss.elastic.co/u/pathfinder225)\
**Post date:** [January 13, 2020, 12:51pm UTC](https://discuss.elastic.co/t/mutiple-filebeat-servers-to-single-logstash-server/214725/4 "2020-01-13T12:51:58Z")

</div>

@Badger and @rugenl

Thank you for the response guys!!

I have figured it now looks like we need one port per one server so. i used pipelines.yml configuration , implemented collector pattern to achieve this so filebeats in 3 servers can connect to logstash on one server using 3 different ports.

here the config.

pipeline.id: beats1  
config.string: |  
input { beats { port =\> 5044 } }  
output { pipeline { send\_to =\> [commonOut] } }

- pipeline.id: beats2  
config.string: |  
input { beats { port =\> 5045 } }  
output { pipeline { send\_to =\> [commonOut] } }
- pipeline.id: beats3  
config.string: |  
input { beats { port =\> 5046 } }  
output { pipeline { send\_to =\> [commonOut] } }
- pipeline.id: partner
# This common pipeline enforces the same logic whether data comes from any number of Beats
config.string: |  
input { pipeline { address =\> commonOut } }  
filter { mutate { remove\_field =\> ["agent","input","ecs"] } }  
output { elasticsearch { hosts =\> ["[http://host](http://host):port"] index =\> "%{[fields][logtype]}-%{+YYYY.MM.dd}" } }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2020, 12:52pm UTC](https://discuss.elastic.co/t/mutiple-filebeat-servers-to-single-logstash-server/214725/5 "2020-02-10T12:52:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
