# When/how often/from where does "filebeat setup -e" need to be run?

**URL:** <https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 5, 2023, 4:31pm UTC](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246 "2023-06-05T16:31:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrew.klaassen](https://avatars.discourse-cdn.com/v4/letter/a/6f9a4e/32.png) [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Post date:** [June 5, 2023, 4:31pm UTC](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246/1 "2023-06-05T16:31:20Z")

</div>

I'm trying to wrap my head around "filebeat setup -e". Let's say I've already got filebeat up and running with a couple of modules, and I want to roll out a new module to a bunch of servers. Which of these would make sense?

1. On _all_ of the servers, change output.elasticsearch.username to filebeat\_internal, run "filebeat setup -e", then change output.elasticsearch.username back to filebeat\_writer.

2. On _one_ of the servers, change output.elasticsearch.username to filebeat\_internal, run "filebeat setup -e", then change output.elasticsearch.username back to filebeat\_writer.

3. On a server where I have filebeat set up but not running, always use filebeat\_internal for output.elasticsearch.username, and run "filebeat setup -e" only on that server after enabling a new module on it.

4. Only run "filebeat setup -e" the first time that filebeat is installed anywhere; don't run it again after new modules are enabled.

Would one or more of those strategies work?

I'm hoping that #3 would work, since that would save me from having to switch the username back and forth between filebeat\_internal and filebeat\_writer every time I roll out a new module. Would it?

Thanks.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 5, 2023, 4:41pm UTC](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246/2 "2023-06-05T16:41:53Z")

</div>

Hi @andrew.klaassen

> [@andrew.klaassen](#):
>
> On a server where I have filebeat set up but not running, always use filebeat\_internal for output.elasticsearch.username, and run "filebeat setup -e" only on that server after enabling a new module on it.

Yes, #3 is a pretty good strategy and I see it often used in larger / automated environmemtns. I think of this Filebeat Setup Host / Install.

You should run setup whenever enabling a new module or when deploying a new version of filebeat across your landscape

The version part is equally important as the templates, pipelines, dashboards can be updated, and templates and pipelines definitions include the version number.

To be clear you _do **not** need to run setup on every_ host, VM, pod, container etc.

---

<div class="post-metadata">

**Author:** ![andrew.klaassen](https://avatars.discourse-cdn.com/v4/letter/a/6f9a4e/32.png) [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Post date:** [June 5, 2023, 4:45pm UTC](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246/3 "2023-06-05T16:45:31Z")

</div>

Thanks, Stephen.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2023, 6:45pm UTC](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246/4 "2023-07-03T18:45:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
