# When/how often/from where does "filebeat setup -e" need to be run?

**URL:** <https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 5, 2023, 4:31pm UTC](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246 "2023-06-05T16:31:20Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 5, 2023, 4:41pm UTC](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246/2 "2023-06-05T16:41:53Z")

</div>

Hi @andrew.klaassen

> [@andrew.klaassen](#):
>
> On a server where I have filebeat set up but not running, always use filebeat\_internal for output.elasticsearch.username, and run "filebeat setup -e" only on that server after enabling a new module on it.

Yes, #3 is a pretty good strategy and I see it often used in larger / automated environmemtns. I think of this Filebeat Setup Host / Install.

You should run setup whenever enabling a new module or when deploying a new version of filebeat across your landscape

The version part is equally important as the templates, pipelines, dashboards can be updated, and templates and pipelines definitions include the version number.

To be clear you _do **not** need to run setup on every_ host, VM, pod, container etc.

---

_[View the full topic](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246)._
