# Running multiple filebeat instances to handle netflow load

**URL:** <https://discuss.elastic.co/t/running-multiple-filebeat-instances-to-handle-netflow-load/284237>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 15, 2021, 2:39am UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances-to-handle-netflow-load/284237 "2021-09-15T02:39:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hjazz6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hjazz6/32/79007_2.png) [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Post date:** [September 15, 2021, 2:39am UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances-to-handle-netflow-load/284237/1 "2021-09-15T02:39:48Z")

</div>

Hi,

I'm currently running Filebeat v7.14 with the Netflow module to send Netflow traffic directly into Elasticsearch. However, when I look at the Filebeat monitoring stats, it appears that I'm dropping packets. I'm thinking of running multiple (maybe 3 or 4 more) instances of filebeat to handle the load.

I've seen the recommendation of using `systemd` to start multiple filebeat services. Is this a feasible way to load-balance the netflow traffic across multiple filebeat instances?

It seems that I have to set different `path.data` for each instance? Is that the only thing I have to change, or can I use the same configuration for all the instances?

---

<div class="post-metadata">

**Author:** ![tomx1](https://avatars.discourse-cdn.com/v4/letter/t/779978/32.png) [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Post date:** [September 16, 2021, 6:19am UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances-to-handle-netflow-load/284237/2 "2021-09-16T06:19:51Z")

</div>

Keep in mind that more than one instance will not help you if they should use the same input. Except you are able to send your netflow events to different ports per instance. I have also a performanceissue with filebeat and netflow, see here: [Performanceissue with Filebeat and Netflow Input](https://discuss.elastic.co/t/performanceissue-with-filebeat-and-netflow-input/284268)

May I ask you how much Events are you able to send through filebeat? In my case it's ~20.000 flows per second, I have to add an additional VM to get 20.000 more which is not a solution. Somehow it must be possible to get better performance with a single filebeat instance.

---

<div class="post-metadata">

**Author:** ![techie.antonio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/techie.antonio/32/77423_2.png) [@techie.antonio](https://discuss.elastic.co/u/techie.antonio)\
**Post date:** [October 6, 2021, 10:21am UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances-to-handle-netflow-load/284237/3 "2021-10-06T10:21:37Z")

</div>

We use the [new ElastiFlow collector](https://docs.elastiflow.com/docs/) because it is provides much better throughput than Logstash (x16) or Filebeat (x4) on the same hardware and also has a lot more features.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2021, 12:21pm UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances-to-handle-netflow-load/284237/4 "2021-11-03T12:21:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
