# Filebeat 6.7.1 high CPU usage

**URL:** <https://discuss.elastic.co/t/filebeat-6-7-1-high-cpu-usage/175493>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 4, 2019, 11:49pm UTC](https://discuss.elastic.co/t/filebeat-6-7-1-high-cpu-usage/175493 "2019-04-04T23:49:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mlaterman](https://avatars.discourse-cdn.com/v4/letter/m/aeb1de/32.png) [@mlaterman](https://discuss.elastic.co/u/mlaterman)\
**Post date:** [April 4, 2019, 11:49pm UTC](https://discuss.elastic.co/t/filebeat-6-7-1-high-cpu-usage/175493/1 "2019-04-04T23:49:02Z")

</div>

I'm observing high CPU utilization with filebeat in trivial cases when running on Amazon Linux  
Given a fresh install of filebeat with the config:

```
filebeat.inputs:
- paths: [/var/log/testlog]
  type: log
logging.level: debug
output.file:
  path: "/tmp/filebeat"
  enabled: true

```

/var/log/testlog is an empty file that I touch on the system.

When I run top I see:

```
  PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND                                                                                                                                                                                                                      
22329 root 20 0 561m 40m 28m S 100.2 8.7 0:27.71 filebeat

```

I'm running filebeat as a service with the init.d script and my registry does not exist on startup.  
This configuration was not creating high CPU usage for 6.3.2  
What's causing the high CPU usage?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [April 5, 2019, 9:39am UTC](https://discuss.elastic.co/t/filebeat-6-7-1-high-cpu-usage/175493/2 "2019-04-05T09:39:42Z")

</div>

Hi,

Would it be possible to run a CPU profile like this:

```auto
filebeat -e --cpuprofile=cpuprofile.pprof

```

Then if you can send us that `cpuprofile.pprof` together the information of which OS you are on would be of great help. Thank you.

---

<div class="post-metadata">

**Author:** ![mlaterman](https://avatars.discourse-cdn.com/v4/letter/m/aeb1de/32.png) [@mlaterman](https://discuss.elastic.co/u/mlaterman)\
**Post date:** [April 5, 2019, 3:19pm UTC](https://discuss.elastic.co/t/filebeat-6-7-1-high-cpu-usage/175493/3 "2019-04-05T15:19:06Z")

</div>

```
[ec2-user@ip-100-76-171-162 ~]$ cat /etc/os-release 
NAME="Amazon Linux AMI"
VERSION="2018.03"
ID="amzn"
ID_LIKE="rhel fedora"
VERSION_ID="2018.03"
PRETTY_NAME="Amazon Linux AMI 2018.03"
ANSI_COLOR="0;33"
CPE_NAME="cpe:/o:amazon:linux:2018.03:ga"
HOME_URL="http://aws.amazon.com/amazon-linux-ami/"

```

Also to note, we are running the dynatrace oneagent on the host (trying to migrate from dynatrace to ELK), I've stopped the agent while running filebeat with pprof.

How should I send the pprof file?

---

<div class="post-metadata">

**Author:** ![mlaterman](https://avatars.discourse-cdn.com/v4/letter/m/aeb1de/32.png) [@mlaterman](https://discuss.elastic.co/u/mlaterman)\
**Post date:** [April 5, 2019, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-6-7-1-high-cpu-usage/175493/4 "2019-04-05T15:58:45Z")

</div>

On further investigation this issue seems to be caused by a dynatrace library on the system, disabling dynatace's golang support resolves the issue. I'll bring the matter up with them. Thanks for the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2019, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-6-7-1-high-cpu-usage/175493/5 "2019-05-03T15:58:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
