# Backpressure behavior and logging with cgroups

**URL:** <https://discuss.elastic.co/t/backpressure-behavior-and-logging-with-cgroups/185272>\
**Category:** Beats\
**Created:** [June 11, 2019, 7:40pm UTC](https://discuss.elastic.co/t/backpressure-behavior-and-logging-with-cgroups/185272 "2019-06-11T19:40:59Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![theterribletrivium](https://avatars.discourse-cdn.com/v4/letter/t/22d042/32.png) [@theterribletrivium](https://discuss.elastic.co/u/theterribletrivium)\
**Post date:** [June 11, 2019, 7:40pm UTC](https://discuss.elastic.co/t/backpressure-behavior-and-logging-with-cgroups/185272/1 "2019-06-11T19:40:59Z")

</div>

I noticed when testing cgroups throttling with auditbeat, the "default" backpressure\_strategy was enabled for auditbeat, if I were to perform a spammy call (i.e. touch /etc/passwd) it would grind to a halt and take over 50 times longer. I was able to set things to userspace and things proceeded with loss of events (as I prefer for this configuration). I noticed this behavior appeared to be mimicked in packetbeat (i.e. the userspace dropping) but it is not configurable.

My questions are:  
-How does packetbeat backpressure work? Is it identical as the userspace configuration for auditbeat?  
-How do I detect when events have been dropped? Is there an event or log entry generated somewhere?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2019, 9:41pm UTC](https://discuss.elastic.co/t/backpressure-behavior-and-logging-with-cgroups/185272/2 "2019-07-09T21:41:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
