# Publish logs from filebeat to multiple (2) logstash instances

**URL:** https://discuss.elastic.co/t/publish-logs-from-filebeat-to-multiple-2-logstash-instances/109480
**Category:** Beats
**Tags:** filebeat
**Created:** [November 28, 2017, 9:48pm UTC](https://discuss.elastic.co/t/publish-logs-from-filebeat-to-multiple-2-logstash-instances/109480 "2017-11-28T21:48:41Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![lokesha](https://avatars.discourse-cdn.com/v4/letter/l/b5a626/32.png) [@lokesha](https://discuss.elastic.co/u/lokesha)
#### Post date: [November 28, 2017, 9:48pm UTC](https://discuss.elastic.co/t/publish-logs-from-filebeat-to-multiple-2-logstash-instances/109480/1 "2017-11-28T21:48:42Z")

</div>

We have a requirement where we need to publish logs from filebeat to multiple logstash instances. Is there any way we can do this?

---

<div class="post-metadata">

### Author: ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)
#### Post date: [November 29, 2017, 2:04pm UTC](https://discuss.elastic.co/t/publish-logs-from-filebeat-to-multiple-2-logstash-instances/109480/2 "2017-11-29T14:04:44Z")

</div>

You can use [Kafka output](https://www.elastic.co/guide/en/beats/filebeat/6.0/kafka-output.html) for this, by sending everything to it and ingesting it into Logstash from many consumer groups

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [November 29, 2017, 2:05pm UTC](https://discuss.elastic.co/t/publish-logs-from-filebeat-to-multiple-2-logstash-instances/109480/3 "2017-11-29T14:05:40Z")

</div>

For this scenario we normally recommend running 2 filebeat instances or kafka. This helps decoupling the two downstream systems (if one is down, the other is still operational).

---

<div class="post-metadata">

### Author: ![lokesha](https://avatars.discourse-cdn.com/v4/letter/l/b5a626/32.png) [@lokesha](https://discuss.elastic.co/u/lokesha)
#### Post date: [December 5, 2017, 5:57pm UTC](https://discuss.elastic.co/t/publish-logs-from-filebeat-to-multiple-2-logstash-instances/109480/4 "2017-12-05T17:57:58Z")

</div>

Thank you @steffens & @exekias for the updates on this since we wanted some quick solution on this requirement so we ended up running 2 filebeat instances.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 2, 2018, 5:57pm UTC](https://discuss.elastic.co/t/publish-logs-from-filebeat-to-multiple-2-logstash-instances/109480/5 "2018-01-02T17:57:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
