# Simultaneous Filebeats to handle high load

**URL:** https://discuss.elastic.co/t/simultaneous-filebeats-to-handle-high-load/260108
**Category:** Beats
**Tags:** filebeat
**Created:** [January 4, 2021, 4:45pm UTC](https://discuss.elastic.co/t/simultaneous-filebeats-to-handle-high-load/260108 "2021-01-04T16:45:34Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![talsh87](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@talsh87](https://discuss.elastic.co/u/talsh87)
#### Post date: [January 4, 2021, 4:45pm UTC](https://discuss.elastic.co/t/simultaneous-filebeats-to-handle-high-load/260108/1 "2021-01-04T16:45:34Z")

</div>

I'd like to leverage Filebeat so it'd fetch our o365\azure\aws logs using the various [modules](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-o365.html).  
How would it handle very high volumes? Is there any benchmark for example events\MBs per second?

Is there any way to maintain a cluster of Filebeat clusters?  
Did anyone encounter situation where one Filebeat per data type (o365\gsuite\azure audit log) wasn't enough?

Seems like in [S3 sqs specifically](https://github.com/elastic/beats/issues/13457) horizontal scaling is feasible, but what about the others?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [January 5, 2021, 12:30am UTC](https://discuss.elastic.co/t/simultaneous-filebeats-to-handle-high-load/260108/2 "2021-01-05T00:30:18Z")

</div>

What sort of volumes are you thinking here?

---

<div class="post-metadata">

### Author: ![talsh87](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@talsh87](https://discuss.elastic.co/u/talsh87)
#### Post date: [January 5, 2021, 7:32am UTC](https://discuss.elastic.co/t/simultaneous-filebeats-to-handle-high-load/260108/3 "2021-01-05T07:32:49Z")

</div>

This is simply an attempt to estimate the options we will have if we choose to use this form of ingestion... understanding what would be the upper limits.  
Thousands of events per second if I'm thinking of O365\Gsuite for example?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 2, 2021, 9:32am UTC](https://discuss.elastic.co/t/simultaneous-filebeats-to-handle-high-load/260108/4 "2021-02-02T09:32:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
