I'm currently running Filebeat v7.14 with the Netflow module to send Netflow traffic directly into Elasticsearch. However, when I look at the Filebeat monitoring stats, it appears that I'm dropping packets. I'm thinking of running multiple (maybe 3 or 4 more) instances of filebeat to handle the load.
I've seen the recommendation of using
systemd to start multiple filebeat services. Is this a feasible way to load-balance the netflow traffic across multiple filebeat instances?
It seems that I have to set different
path.data for each instance? Is that the only thing I have to change, or can I use the same configuration for all the instances?