# About the time spent when output to elasticsearch

**URL:** <https://discuss.elastic.co/t/about-the-time-spent-when-output-to-elasticsearch/143290>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 7, 2018, 9:14am UTC](https://discuss.elastic.co/t/about-the-time-spent-when-output-to-elasticsearch/143290 "2018-08-07T09:14:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 7, 2018, 9:14am UTC](https://discuss.elastic.co/t/about-the-time-spent-when-output-to-elasticsearch/143290/1 "2018-08-07T09:14:30Z")

</div>

Hi, I am trying filebeat output to elasticsearch. And have something not clear.  
And I found that there are almost 7 seconds among filebeat publish to elasticsearch and elasticsearch API can find the doc. (Filebeat just sent two logs.)  
What had happened during these times. Can we reduce these times spent?

Best.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 7, 2018, 10:06am UTC](https://discuss.elastic.co/t/about-the-time-spent-when-output-to-elasticsearch/143290/2 "2018-08-07T10:06:34Z")

</div>

Hi @cythwell,

How are you checking the time filebeat pubish to elasticsearch?

There can be some things that include a delay between the time a log line is written and it is available into elasticsearch:

- There are some settings in filebeat that can control how files are scanned, depending on how files are read, there can be some lag.
- Once the line is read, events are kept in an [internal queue](https://www.elastic.co/guide/en/beats/filebeat/6.3/configuring-internal-queue.html), so they can be sent in batches.
- Once the event is received by elasticsearch, it has to refresh the index, beats indexes are configured to be refreshed every 5 seconds.

Most of it can be configured in filebeat or in its indexes, but take into account that modifying these values can increase the load in your systems.

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 7, 2018, 10:27am UTC](https://discuss.elastic.co/t/about-the-time-spent-when-output-to-elasticsearch/143290/3 "2018-08-07T10:27:41Z")

</div>

Hi @jsoriano, thanks for your reply  
I was running filebeat in debug mode and count the time when the publish info print out, and tried call api to get the doc. Test for server times and it was about to 7 seconds. Btw , I saw that the time record of "read\_timestamp" and "@timestamp" , also have about 7 seconds period. And for your suggest,

There are some settings in filebeat that can control how files are scanned, depending on how files are read, there can be some lag.  
For this, I had already set the scan\_frenquency to 1S, Does it still has others setting can help?

Once the line is read, events are kept in an internal queue, so they can be sent in batches.  
Do you mean "max\_bulk\_size", I was not setting this, so it should be the default 50, right?  
And I just sent two logs in my test case. Do you mean that the log add into queue and wait for a period then sent to elasticsearch? Can you explain when will filebeat sent out the log?

Once the event is received by elasticsearch, it has to refresh the index, beats indexes are configured to be refreshed every 5 seconds.  
Yes. But as I just sent out 2 logs. I think this stage will fast enough, am I right?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 7, 2018, 12:24pm UTC](https://discuss.elastic.co/t/about-the-time-spent-when-output-to-elasticsearch/143290/4 "2018-08-07T12:24:24Z")

</div>

> [@cythwell](#):
>
> For this, I had already set the scan\_frenquency to 1S, Does it still has others setting can help?

Take a look to [log input options](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html), you might try to customize the backoff settings. In any case I don't thing this will affect your observed time, as you are counting the time since the publish info is printed.

> [@cythwell](#):
>
> Do you mean "max\_bulk\_size", I was not setting this, so it should be the default 50, right?  
> And I just sent two logs in my test case. Do you mean that the log add into queue and wait for a period then sent to elasticsearch? Can you explain when will filebeat sent out the log?

You can also try to reduce [`flush.min_events`](https://www.elastic.co/guide/en/beats/filebeat/6.3/configuring-internal-queue.html#_literal_flush_min_events_literal) and [`flush.timeout`](https://www.elastic.co/guide/en/beats/filebeat/6.3/configuring-internal-queue.html#_literal_flush_timeout_literal).

> [@cythwell](#):
>
> Yes. But as I just sent out 2 logs. I think this stage will fast enough, am I right?

The process is done every 5 seconds, no matter the number of logs. To check if this is what is increasing your times, try to reduce the `refresh_interval` for the index you are writing to. With a query like this one:

```auto
PUT /<your filebeat index>/_settings
{
    "index" : {
        "refresh_interval" : "1s"
    }
}

```

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 8, 2018, 2:43am UTC](https://discuss.elastic.co/t/about-the-time-spent-when-output-to-elasticsearch/143290/5 "2018-08-08T02:43:51Z")

</div>

Hi @jsoriano, thanks for your suggestion. I think these should help. But I just found something strange,  
and I think I should resolve it first.  
I access my nginx web, and there is a log generated in nginx access log. Then I can see filebeate publish a log event. But at the end, I can found two same doc inside elasticsearch. Seems elasticsearch do a copy and regard it as new doc..  
Any idea?

My filebeat version is 6.3.2, and my config:  
filebeat.yml

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a61fa0057b0037a1893f583820e19036046efec.png)

nginx.yml:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7c57766a28d5e08607b96d2801610b3e2f0cdaf4.png)

Thanks

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 8, 2018, 3:59am UTC](https://discuss.elastic.co/t/about-the-time-spent-when-output-to-elasticsearch/143290/6 "2018-08-08T03:59:19Z")

</div>

Sorry @jsoriano. Ignore the elasticsearch repeat log. It is my fault, someone start the filebeat service while I running the filebeat debug. So there are two filebeat running at the same time.

Back to the time spent problem. I am sorry but after I setting the fulsh.min\_events , flush.timemout, and refresh\_interval . I had tried setup the setting and test one by one, but still no luck.  
Sometime it could fast(less than 1s), but sometime is also need 7 seconds or more.

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 8, 2018, 7:05am UTC](https://discuss.elastic.co/t/about-the-time-spent-when-output-to-elasticsearch/143290/7 "2018-08-08T07:05:34Z")

</div>

Seems scan\_frequency not work perfectly after I had those setup.  
Sometime it can scan the log file changed immediately and publish, at this case, the api can find the new document very fast.  
Sometime it kept scan the log file but can not realize the file changed, so it can not publish the doc at time， at this case, the api will have some scends delay.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 5, 2018, 7:05am UTC](https://discuss.elastic.co/t/about-the-time-spent-when-output-to-elasticsearch/143290/8 "2018-09-05T07:05:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
