# Running multiple filebeat instances

**URL:** https://discuss.elastic.co/t/running-multiple-filebeat-instances/305423
**Category:** Beats
**Tags:** docker, filebeat
**Created:** [May 23, 2022, 6:18pm UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances/305423 "2022-05-23T18:18:27Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![justplanenutz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justplanenutz/32/106054_2.png) [@justplanenutz](https://discuss.elastic.co/u/justplanenutz)
#### Post date: [May 23, 2022, 6:18pm UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances/305423/1 "2022-05-23T18:18:27Z")

</div>

We have a system that is very chatty with regard to the number of logs produced. Our current production implementation has a single filebeat container ( in k8s ) running and it is struggling to keep up. We have adjusted resources, adding CPU and memory, but we still end up in a crash loop from time to time.

Is it possible to have 2 filebeat pods looking at the same globbed path and using a common registry to spread the load and provide some redundancy?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [May 23, 2022, 8:09pm UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances/305423/2 "2022-05-23T20:09:04Z")

</div>

I don't think it is possible, each filebeat instanve needs to have its own registry.

How have you identified that filebeat is the bottleneck and not Elasticsearch?

Have you already played with different values for the number of workers and the bulk size [[documentation](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html)] ?

---

<div class="post-metadata">

### Author: ![justplanenutz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justplanenutz/32/106054_2.png) [@justplanenutz](https://discuss.elastic.co/u/justplanenutz)
#### Post date: [May 23, 2022, 8:59pm UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances/305423/3 "2022-05-23T20:59:07Z")

</div>

I kept looking for the worker config in the reader, never occurred to me that it was in the writer side. Thank you for the insight... this helps.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 20, 2022, 10:59pm UTC](https://discuss.elastic.co/t/running-multiple-filebeat-instances/305423/4 "2022-06-20T22:59:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
