# File Beat Consuming very high CPU

**URL:** https://discuss.elastic.co/t/file-beat-consuming-very-high-cpu/71618
**Category:** Beats
**Tags:** filebeat
**Created:** [January 14, 2017, 4:10pm UTC](https://discuss.elastic.co/t/file-beat-consuming-very-high-cpu/71618 "2017-01-14T16:10:48Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![userguy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/userguy/32/6224_2.png) [@userguy](https://discuss.elastic.co/u/userguy)
#### Post date: [January 14, 2017, 4:10pm UTC](https://discuss.elastic.co/t/file-beat-consuming-very-high-cpu/71618/1 "2017-01-14T16:10:48Z")

</div>

Hello Team ,

This is my configuration  
filebeat version 5.0.0-1 with centos 7 and also it directly inserts into kafka

These are the events in filebeat

INFO Non-zero metrics in the last 30s: registrar.states.update=8935 publish.events=8935 libbeat.kafka.call\_count.PublishEvents=6 libbeat.kafka.published\_and\_acked\_events=8935 libbeat.publisher.published\_events=8935 registrar.writes=6  
INFO Non-zero metrics in the last 30s: registrar.states.update=8495 registrar.writes=5 libbeat.kafka.call\_count.PublishEvents=6 libbeat.publisher.published\_events=10372 libbeat.kafka.published\_and\_acked\_events=8495 publish.events=8495  
INFO Non-zero metrics in the last 30s: registrar.writes=11 registrar.states.update=22357 libbeat.kafka.call\_count.PublishEvents=10 libbeat.publisher.published\_events=20480 libbeat.kafka.published\_and\_acked\_events=22357 publish.events=22357  
INFO Non-zero metrics in the last 30s: publish.events=15430 libbeat.kafka.published\_and\_acked\_events=15430 registrar.writes=8 libbeat.kafka.call\_count.PublishEvents=9 libbeat.publisher.published\_events=17478 registrar.states.update=15430  
INFO Non-zero metrics in the last 30s: registrar.writes=12 publish.events=24576 libbeat.kafka.call\_count.PublishEvents=11 libbeat.publisher.published\_events=22528 libbeat.kafka.published\_and\_acked\_events=24576 registrar.states.update=24576

filebeat.prospectors:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

- input\_type: log  
paths:

logging.to\_files: true  
logging.files:  
path: /var/log/filebeat

Cpu : overshoots to more than 100% and it is only affinity is to single cpu

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [January 16, 2017, 4:01pm UTC](https://discuss.elastic.co/t/file-beat-consuming-very-high-cpu/71618/2 "2017-01-16T16:01:21Z")

</div>

1. cpu affinity. Same CPU or same Core? This is somewhat due to the OS/kernel scheduling the OS-threads. The scheduling might not be always optimal (on linux tools like taskset do help). On the other hand, having a multi-core processor I'd favor my process running on the same CPU to reduce potential communcation required if data are passed to a worker running on another CPU.

2. These are not that many events being published. This makes me wonder about potential network/kafka problems requiring the client to retry sending. At worst this might generate some garbage to be collected as well.

3. Without profiling I can not really tell if there are any hotspots. In case you don't have a (don't want to) go development environment installed, you can easiliy get a profile via http. Just start filebeat with `-httpprof 127.0.0.1:6060`. This starts an http server (reachable from localhost only) you can use your browser or curl/wget to sample a full stack-trace every 10 seconds from : [http://localhost:6060/debug/pprof/profile?debug=3](http://localhost:6060/debug/pprof/profile?debug=3) . Or use `wget http://localhost:6060/debug/pprof/trace?seconds=20` to collect a profile over the course of 20 seconds.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 13, 2017, 4:01pm UTC](https://discuss.elastic.co/t/file-beat-consuming-very-high-cpu/71618/3 "2017-02-13T16:01:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
