# Performance Filebeat in a webhosting environment

**URL:** <https://discuss.elastic.co/t/performance-filebeat-in-a-webhosting-environment/172355>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 14, 2019, 2:39pm UTC](https://discuss.elastic.co/t/performance-filebeat-in-a-webhosting-environment/172355 "2019-03-14T14:39:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![michali](https://avatars.discourse-cdn.com/v4/letter/m/91b2a8/32.png) [@michali](https://discuss.elastic.co/u/michali)\
**Post date:** [March 14, 2019, 2:39pm UTC](https://discuss.elastic.co/t/performance-filebeat-in-a-webhosting-environment/172355/1 "2019-03-14T14:39:50Z")

</div>

Hey

I'm doing an internship at a hosting company and I got a question about what gives us the best performance. The endgoal is to pipe all apache and php logfiles into Logstash.

The options are:

1. Push all apache files to one file (localy) and read it from there with Filebeat.
2. Let Filebeat check every location (150+) and push them to Logstash.

Is there any difference?

Additional question:

Is there any advantage if I use a module like "apache module" on Filebeat to send the the logs to Logstash, or do I send them directly to Elasticsearch?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 15, 2019, 2:05pm UTC](https://discuss.elastic.co/t/performance-filebeat-in-a-webhosting-environment/172355/2 "2019-03-15T14:05:08Z")

</div>

Filebeat modules offload parsing to Ingest Node in Elasticsearch. If you want to do your own processing in Logstash, you should better use inputs directly.

150+ files is a many files. You should run some tests though. Too many files in one directory can be a problem, but 150 files is not too many yet I think. In the end it depends on a few factors like OS, filesystem, actual log write patterns over time.

> Push all apache files to one file (localy) and read it from there with Filebeat

It's an option, but common pitfalls with this practice:

- Combined logs should have same format, so to simplify processing/filtering needs
- Do not intermix multiline logs in one file. You might not be able to reconstructs those multiline events properly.

I guess the later is more about stack traces from your php logs.

My advice is to always test and get an idea how the different options perform. Do not optimise/tune if the system already operates/performs up to expectations. The simpler the setup, the less you have to modify, the better.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2019, 2:05pm UTC](https://discuss.elastic.co/t/performance-filebeat-in-a-webhosting-environment/172355/3 "2019-04-12T14:05:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
