# Data loss happening somewhere

**URL:** <https://discuss.elastic.co/t/data-loss-happening-somewhere/62390>\
**Category:** Logstash\
**Created:** [October 6, 2016, 2:05pm UTC](https://discuss.elastic.co/t/data-loss-happening-somewhere/62390 "2016-10-06T14:05:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shimon\_k](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@Shimon\_k](https://discuss.elastic.co/u/Shimon_k)\
**Post date:** [October 6, 2016, 2:05pm UTC](https://discuss.elastic.co/t/data-loss-happening-somewhere/62390/1 "2016-10-06T14:05:47Z")

</div>

Hi guys,

I am totally lost with this issue, I spent countless hours trying to figure it out but I came up empty. It seems like somewhere along the process from input into Logstash to the ingestion into Elastic data is being lost. I looked through the Logstash logs but found no errors. I have been running almost an identical config file in a second cluster and the second cluster is working fine and ingesting way more.

I know that I should be seeing at least four times the amount of data then what I see now. I am attaching a screenshot below of the ingestion rate into Elastic. You can see the sharp rises and falls in the graph, and that its not coming in steady. I cant seem to figure out whether its even an Elastic or Logstash issue. Any help would be awesome!

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/2afbb5ee7a7e2b06e8c3f69e17fdd125f7a96541.PNG)

---

<div class="post-metadata">

**Author:** ![Shimon\_k](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@Shimon\_k](https://discuss.elastic.co/u/Shimon_k)\
**Post date:** [October 6, 2016, 5:29pm UTC](https://discuss.elastic.co/t/data-loss-happening-somewhere/62390/2 "2016-10-06T17:29:31Z")

</div>

Hi I have found that this is helping me solve a issue with logstash getting clogged up. I am sending a huge amount a data through it, the machine has 128GB of RAM and a 16 core CPU. I found that by raising the LS\_Heap size, the number of workers, and the batch size is helping it process this large amount of data.

My question now is, how many workers can I afford to give it? I have plenty of free RAM, but I know its not recommended to exceed the number of CPU cores. Can I go above 16?

Its getting better but still clogged up...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:35am UTC](https://discuss.elastic.co/t/data-loss-happening-somewhere/62390/3 "2017-07-06T04:35:21Z")

</div>


