# BottleNeck in local beats input

**URL:** <https://discuss.elastic.co/t/bottleneck-in-local-beats-input/232871>\
**Category:** Logstash\
**Created:** [May 15, 2020, 7:14pm UTC](https://discuss.elastic.co/t/bottleneck-in-local-beats-input/232871 "2020-05-15T19:14:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aerodynamic](https://avatars.discourse-cdn.com/v4/letter/a/bc79bd/32.png) [@aerodynamic](https://discuss.elastic.co/u/aerodynamic)\
**Post date:** [May 15, 2020, 7:14pm UTC](https://discuss.elastic.co/t/bottleneck-in-local-beats-input/232871/1 "2020-05-15T19:14:05Z")

</div>

Hello,

I'm currently facing a bottleneck with Logstash. Currently my project is a single linux box running the FELK stack. I have determined that Logstash is a bottleneck by having filebeats write to a file (where I get 100mb per second). But when I connect to my Logstash beats port the rate drops down to nearly a fourth.

What can I do to improve performance here?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 15, 2020, 7:23pm UTC](https://discuss.elastic.co/t/bottleneck-in-local-beats-input/232871/2 "2020-05-15T19:23:12Z")

</div>

How do you know Logstash and not Elasticsearch is the bottleneck? Have you configured Logstash to write to file as well?

---

<div class="post-metadata">

**Author:** ![aerodynamic](https://avatars.discourse-cdn.com/v4/letter/a/bc79bd/32.png) [@aerodynamic](https://discuss.elastic.co/u/aerodynamic)\
**Post date:** [May 18, 2020, 8:57pm UTC](https://discuss.elastic.co/t/bottleneck-in-local-beats-input/232871/3 "2020-05-18T20:57:57Z")

</div>

I can't be certain it's not an elasticsearch issue. That's a good point. Logstash doesn't write to a file. It's simply writes to ES

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 19, 2020, 5:09am UTC](https://discuss.elastic.co/t/bottleneck-in-local-beats-input/232871/4 "2020-05-19T05:09:04Z")

</div>

If you change it to write to file and throughput increases you have an indication that it is Elasticsearch you need to look at and not Logstash. If Elasticsearch is the limiting factor there is no point tuning Logstash.

---

<div class="post-metadata">

**Author:** ![aerodynamic](https://avatars.discourse-cdn.com/v4/letter/a/bc79bd/32.png) [@aerodynamic](https://discuss.elastic.co/u/aerodynamic)\
**Post date:** [May 20, 2020, 7:39pm UTC](https://discuss.elastic.co/t/bottleneck-in-local-beats-input/232871/5 "2020-05-20T19:39:48Z")

</div>

Right. I will get back to you on this approach. My team has been testing a different architecture which has led to a different problem. Hoping to come back to this shortly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2020, 7:39pm UTC](https://discuss.elastic.co/t/bottleneck-in-local-beats-input/232871/6 "2020-06-17T19:39:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
