# Send logs From Filebeat to 2 different logstash servers simultaneously

**URL:** https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-different-logstash-servers-simultaneously/212572
**Category:** Logstash
**Created:** [December 19, 2019, 11:15pm UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-different-logstash-servers-simultaneously/212572 "2019-12-19T23:15:32Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![saravananveera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saravananveera/32/59765_2.png) [@saravananveera](https://discuss.elastic.co/u/saravananveera)
#### Post date: [December 19, 2019, 11:15pm UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-different-logstash-servers-simultaneously/212572/1 "2019-12-19T23:15:33Z")

</div>

Hi Team,

My requirement is to configure filebeat output as two logstash servers and I need to send logs to defined 2 servers simultaneously. It is not load balance scenario. Both logstash servers should received same data. Could you please help me.

Filebeat output conf:

#-------------------------- Kafka Output ----------------------------------  
output.kafka:  
#initial brokers for reading cluster metadata  
hosts: ["130.99.212.103:9092", "61.85.172.183:9092"]

#message topic selection + partitioning  
topic: 'testlog'  
partition.round\_robin:  
reachable\_only: false

# required\_acks: 1 compression: gzip max\_message\_bytes: 1000000

Error log from 2nd logstash:

[2019-12-19T23:03:55,292][ERROR][logstash.agent] Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}

Note: i'm getting log from filebeat to 1st logstash.

---

<div class="post-metadata">

### Author: ![saravananveera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saravananveera/32/59765_2.png) [@saravananveera](https://discuss.elastic.co/u/saravananveera)
#### Post date: [December 26, 2019, 10:46am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-different-logstash-servers-simultaneously/212572/2 "2019-12-26T10:46:10Z")

</div>

Any one please help me

---

<div class="post-metadata">

### Author: ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)
#### Post date: [December 27, 2019, 3:27pm UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-different-logstash-servers-simultaneously/212572/3 "2019-12-27T15:27:03Z")

</div>

Your requirement can be fulfilled by configuring two different output.logstash sections, each one with a different logstash host, as seen in the documentation [https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html)

Your output, however, shows a sample [kafka output configuration](https://www.elastic.co/guide/en/beats/filebeat/current/kafka-output.html)  
If you are using kafka as message broker between filebeats and logstash indexers, the logical step should be to configure kafka topics and consumer groups to allow each message to be consumed by different logstash indexers. In that case, you should ask for kafka support.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 24, 2020, 3:27pm UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-different-logstash-servers-simultaneously/212572/4 "2020-01-24T15:27:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
