# Cluster ID "5d1f1d" - Logstash startup is super slow

**URL:** <https://discuss.elastic.co/t/cluster-id-5d1f1d-logstash-startup-is-super-slow/85963>\
**Category:** Logstash\
**Created:** [May 16, 2017, 3:12pm UTC](https://discuss.elastic.co/t/cluster-id-5d1f1d-logstash-startup-is-super-slow/85963 "2017-05-16T15:12:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![vidagh](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@vidagh](https://discuss.elastic.co/u/vidagh)\
**Post date:** [May 16, 2017, 3:12pm UTC](https://discuss.elastic.co/t/cluster-id-5d1f1d-logstash-startup-is-super-slow/85963/1 "2017-05-16T15:12:28Z")

</div>

Hi,

Logstash is taking hours to execute as the filter size is growing, and CPU usage goes to max.

It works fine for a parser of around 2000 lines, but then it would slow down, almost stops, as it grows.

CentOS machine, Logstash version 5.3.2, Java version Open JDK 1.8; and haveged is installed and enabled.

Any suggestions on what can be the cause of it, is highly appreciated.

Thanks,  
Vida

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 16, 2017, 10:31pm UTC](https://discuss.elastic.co/t/cluster-id-5d1f1d-logstash-startup-is-super-slow/85963/2 "2017-05-16T22:31:33Z")

</div>

[https://github.com/jruby/jruby/wiki/Improving-startup-time](https://github.com/jruby/jruby/wiki/Improving-startup-time) may be helpful.

---

<div class="post-metadata">

**Author:** ![vidagh](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@vidagh](https://discuss.elastic.co/u/vidagh)\
**Post date:** [May 17, 2017, 8:12am UTC](https://discuss.elastic.co/t/cluster-id-5d1f1d-logstash-startup-is-super-slow/85963/3 "2017-05-17T08:12:27Z")

</div>

Thank you @warkolm, have tried all this but it is not helping! I assume the nature of the Logstash is to run large amount of data!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 17, 2017, 9:21am UTC](https://discuss.elastic.co/t/cluster-id-5d1f1d-logstash-startup-is-super-slow/85963/4 "2017-05-17T09:21:22Z")

</div>

How slow are you talking?  
What's your config look like?

---

<div class="post-metadata">

**Author:** ![vidagh](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@vidagh](https://discuss.elastic.co/u/vidagh)\
**Post date:** [May 17, 2017, 9:37am UTC](https://discuss.elastic.co/t/cluster-id-5d1f1d-logstash-startup-is-super-slow/85963/5 "2017-05-17T09:37:20Z")

</div>

The config file is a grok filter which normalises data, followed by an extensive list of if conditions to add more fields to the normalised data. The if conditions are let's say around 4000 in number for a single config file and it would take up to 5, 6 for Logstash to ingest the data and starts successfully.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 17, 2017, 9:38am UTC](https://discuss.elastic.co/t/cluster-id-5d1f1d-logstash-startup-is-super-slow/85963/6 "2017-05-17T09:38:19Z")

</div>

That's pretty massive, so not surprising it takes a while.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2017, 9:38am UTC](https://discuss.elastic.co/t/cluster-id-5d1f1d-logstash-startup-is-super-slow/85963/7 "2017-06-14T09:38:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
