# Benchmarking Filebeats

**URL:** <https://discuss.elastic.co/t/benchmarking-filebeats/79746>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 23, 2017, 12:47pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746 "2017-03-23T12:47:30Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [March 23, 2017, 12:47pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/1 "2017-03-23T12:47:30Z")

</div>

> [@Filebeat sending data to Logstash seems too slow](https://discuss.elastic.co/t/filebeat-sending-data-to-logstash-seems-too-slow/37596/13):
>
> why not set bulk\_max\_size=2048? I found 4k and 2k much better for throughput in comparison to. with this many workers on physical machine with 16 cores I measured like 45k lines/s. some ways to measure performance and look for bottlenecks: have filebeat publish to console and redirect to /dev/null. Alternatively configure file output in filebeat have filebeat-\>logstash, but configure logstash stdout plugin only with 'dots' codec. Use pv to measure throughput. run filebeat-\>logstash-\>elasticse…

As explained in this post I enabled my filebeat with very simple configurations as startup.

```
filebeat.prospectors:
- input_type: log
  paths:
    - /root/*.log
  ignore_older: 5m
  scan_frequency: 10s
  close_inactive: 10m
output.kafka:
  hosts: ["172.16.23.27:9092"]
  topic: prem

```

After I run `./filebeat -c filebeat.kafka.yml -httpprof :6060`

Then I am running the `expvar_rates.py`. But its showing error and I cannot get any result. I am using 5.2.2 filebeat, 0.9 kafka & 2.7 python.

`Traceback (most recent call last): File "expvar_rates.py", line 64, in <module> main() File "expvar_rates.py", line 31, in main json = r.json() File "/usr/lib/python2.6/site-packages/requests/models.py", line 866, in json return complexjson.loads(self.text, **kwargs) File "/usr/lib64/python2.6/site-packages/simplejson/ __init__.py", line 307, in loads return _default_decoder.decode(s) File "/usr/lib64/python2.6/site-packages/simplejson/decoder.py", line 338, in decode raise ValueError(errmsg("Extra data", s, end, len(s))) ValueError: Extra data: line 1 column 4 - line 2 column 1 (char 4 - 19)`

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [March 23, 2017, 1:06pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/2 "2017-03-23T13:06:10Z")

</div>

What command do you use to start the `expvar_rates.py` script? Is [this](https://gist.github.com/tsg/09244c3dc53a0ead207cb7c09d5dfd63) the version that you use?

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [March 23, 2017, 1:15pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/3 "2017-03-23T13:15:13Z")

</div>

I copied my script from the same mentioned link.

> [@Filebeat sending data to Logstash seems too slow](https://discuss.elastic.co/t/filebeat-sending-data-to-logstash-seems-too-slow/37596/13):
>
> why not set bulk\_max\_size=2048? I found 4k and 2k much better for throughput in comparison to. with this many workers on physical machine with 16 cores I measured like 45k lines/s. some ways to measure performance and look for bottlenecks: have filebeat publish to console and redirect to /dev/null. Alternatively configure file output in filebeat have filebeat-\>logstash, but configure logstash stdout plugin only with 'dots' codec. Use pv to measure throughput. run filebeat-\>logstash-\>elasticse…

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [March 23, 2017, 1:18pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/4 "2017-03-23T13:18:47Z")

</div>

The error seems to indicate that the server returns invalid JSON. Can you do a `curl http://localhost:6060/debug/vars` and check that the answer looks valid?

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [March 23, 2017, 1:24pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/5 "2017-03-23T13:24:21Z")

</div>

I am getting one big JSON. But how can I say that its valid are not???

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [March 23, 2017, 1:31pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/6 "2017-03-23T13:31:04Z")

</div>

Some of the intresting counters.. Cant paste total object (too big)

```
   "filebeat.harvester.closed": 5,
    "filebeat.harvester.open_files": 2,
      "filebeat.harvester.running": 2,
      "libbeat.kafka.call_count.PublishEvents": 7738,
      "libbeat.kafka.published_and_acked_events": 9188705,
     "libbeat.publisher.published_events": 9189729,
```

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [March 23, 2017, 1:58pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/7 "2017-03-23T13:58:08Z")

</div>

Thanks your version is working for me. But can you explain that

Is this the count my beat is pushing

`publish.events: 34595.7300882/s (avg: 29292.9529271/s) (total: 7473152)`

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [March 23, 2017, 4:00pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/8 "2017-03-23T16:00:35Z")

</div>

Yes, it seems to be able to push around 30 K/s.

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [March 24, 2017, 5:51am UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/9 "2017-03-24T05:51:22Z")

</div>

For me this is enough. But its using 200% (complete 2 cores) in 8 core server. Can I able to reduce this cpu consumption. I am using all default configurations only.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [March 24, 2017, 10:38am UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/10 "2017-03-24T10:38:05Z")

</div>

If you want, you can restrict it to a single core by using the GOMAXPROCS env variable, but the throughput will likely go down. From our benchmarks, most of the time is spent in JSON encoding, and we are looking for ways to improve that.

If you are curious, you can do your own profile by using the `-httpprof` option.

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [April 4, 2017, 5:00am UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/11 "2017-04-04T05:00:59Z")

</div>

Can you please explain how to do my own profiling using this `-httpprof`?? It will help us a lot

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [April 5, 2017, 1:46pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/12 "2017-04-05T13:46:28Z")

</div>

These two links should help:

- [https://gowalker.org/net/http/pprof](https://gowalker.org/net/http/pprof)
- [https://blog.golang.org/profiling-go-programs](https://blog.golang.org/profiling-go-programs)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2017, 1:46pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746/13 "2017-05-03T13:46:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
