# Running filebeat as ECS daemon

**URL:** https://discuss.elastic.co/t/running-filebeat-as-ecs-daemon/224958
**Category:** Beats
**Tags:** filebeat
**Created:** [March 25, 2020, 9:00am UTC](https://discuss.elastic.co/t/running-filebeat-as-ecs-daemon/224958 "2020-03-25T09:00:57Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![ConorTier](https://avatars.discourse-cdn.com/v4/letter/c/6de8d8/32.png) [@ConorTier](https://discuss.elastic.co/u/ConorTier)
#### Post date: [March 25, 2020, 9:07am UTC](https://discuss.elastic.co/t/running-filebeat-as-ecs-daemon/224958/2 "2020-03-25T09:07:02Z")

</div>

hey perhaps see my description of a setup

if daemon and 3 nodes in cluster then 3 filebeat instances all reading from 1 volumn - could be a problem, and daemon will have root access to node but not pods files as far ias i know - my testing

> [@Filebeats Kubernetes File close due to inactive of 5min](https://discuss.elastic.co/t/filebeats-kubernetes-file-close-due-to-inactive-of-5min/224855/2):
>
> Little more background in case it helps - Microservices created in .net core - using log4net logging - file appender - this should not matter as its just creating a something.log file with a specific format for each log output. Havent changed the scan\_frequency - default is 10 seconds and close\_inactive is still at its default - (5 mintues) In theory once a log entry is entered every 10 minutes as example - it should appear to filebeat output every 10 minutes and 10 seconds - note logs dont co…

---

_[View the full topic](https://discuss.elastic.co/t/running-filebeat-as-ecs-daemon/224958)._
