# Bootstrap.mlock setting

**URL:** <https://discuss.elastic.co/t/bootstrap-mlock-setting/103073>\
**Category:** Elasticsearch\
**Created:** [October 6, 2017, 7:42pm UTC](https://discuss.elastic.co/t/bootstrap-mlock-setting/103073 "2017-10-06T19:42:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![corona](https://avatars.discourse-cdn.com/v4/letter/c/958977/32.png) [@corona](https://discuss.elastic.co/u/corona)\
**Post date:** [October 6, 2017, 7:42pm UTC](https://discuss.elastic.co/t/bootstrap-mlock-setting/103073/1 "2017-10-06T19:42:58Z")

</div>

Hello,

We are currently running a cluster with 20 nodes 49800 shards and version 2.4.0. Recently I set the bootstrap.mlockall setting to true. Over the span of a month, I've observed the nodes with this setting have slowly increased their swap space usage. One node went to as high as 1GB of swap. I'm wondering if there are additional steps I need to take to ensure this is working properly? Is this setting supposed to ensure no swapping will occur for that node, or is it more like the node won't swap unless it absolutely has to? Any clarification you can provide here would be helpful.

Most likely I won't be able to disable all swapping as these servers are running other processes, which may require swapping. I'll have to investigate that some more to confirm. That said, can you provide some advice for what to do if you can't disable swapping on the server, but would like ensure ElasticSearch is not swapping? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 6, 2017, 9:07pm UTC](https://discuss.elastic.co/t/bootstrap-mlock-setting/103073/2 "2017-10-06T21:07:09Z")

</div>

If you cannot disable swap, then setting `bootstrap.mlockall: true` is the best way. Elasticsearch should report that it is applied on startup, if you check the log.

> [@corona](#):
>
> 20 nodes 49800 shards

That's too many, you need to reduce this as it's likely causing issues.

---

<div class="post-metadata">

**Author:** ![corona](https://avatars.discourse-cdn.com/v4/letter/c/958977/32.png) [@corona](https://discuss.elastic.co/u/corona)\
**Post date:** [October 10, 2017, 2:48pm UTC](https://discuss.elastic.co/t/bootstrap-mlock-setting/103073/3 "2017-10-10T14:48:21Z")

</div>

Thanks for the response. So I checked the log and I don't see anything specifically called out to indicate it's set. Is it at the INFO level? I do see a warning which says,

"unable to install sys call filter: seccomp unavailable: CONFIG\_SECCOMP not compiled into kernel, CONFIG\_SECCOMP and CONFIG\_SECCOMP\_FILTER are needed.

Through various google searches, I believe I determined that warning can be ignored. Is that not the case? Aside from the log is there another method for determining it was enabled properly?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2017, 2:49pm UTC](https://discuss.elastic.co/t/bootstrap-mlock-setting/103073/4 "2017-11-07T14:49:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
