# Filebeat beta1: Insane memory footprint

**URL:** <https://discuss.elastic.co/t/filebeat-beta1-insane-memory-footprint/61998>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 1, 2016, 11:58pm UTC](https://discuss.elastic.co/t/filebeat-beta1-insane-memory-footprint/61998 "2016-10-01T23:58:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shog/32/12138_2.png) [@shog](https://discuss.elastic.co/u/shog)\
**Post date:** [October 1, 2016, 11:58pm UTC](https://discuss.elastic.co/t/filebeat-beta1-insane-memory-footprint/61998/1 "2016-10-01T23:58:32Z")

</div>

Hi,

Version: Filebeat beta1  
System: CentOS6

I observe an insane memory footprint of filebeat beta1.

```auto
  PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND            
23818 filebeat 15 -5 30.5g 27g 1556 S 13.9 57.6 593:35.22 filebeat           

```

This is only after ~20hrs of process uptime. On this host I have four prospectors defined and they are scanning around 2000 files, which are in total worth less than 13GB.

Settings that might potentially be interesting:

```auto
      harvester_buffer_size: 131072
  publish_async: true

```

I see similar memory pattern across entire beta1 setup. Please let me know what info would be valuable for you to track issue. I did not observe this with alpha5.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 2, 2016, 1:33am UTC](https://discuss.elastic.co/t/filebeat-beta1-insane-memory-footprint/61998/2 "2016-10-02T01:33:48Z")

</div>

What does your config look like?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 3, 2016, 9:01am UTC](https://discuss.elastic.co/t/filebeat-beta1-insane-memory-footprint/61998/3 "2016-10-03T09:01:28Z")

</div>

Can you please share the full config files and the log files if possible? Which other beats are you running? What is your setup? beats -\> LS -\> ES? Is the memory constantly increasing or do you see it going up and down?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 4, 2016, 1:31pm UTC](https://discuss.elastic.co/t/filebeat-beta1-insane-memory-footprint/61998/4 "2016-10-04T13:31:03Z")

</div>

please share full output section in filebeat.yml and other settings, but prospectors. The `publish_async` option looks `telling`. But as `publish_async` changes interaction with output I need to know about outputs in order to figure there might be some issue. You using multiline? Have you checked filebeat logs for output errors (e.g. EOF or connections being dropped)?

In prospectors have you a common strategy using any of the `close_...` settings?

Have you tried to disable `publish_async`?

Filebeat supports generation of a memory profile using `-memprofile <out file name>`. Can you run filebeat with this setting and share the generated profile with us?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2016, 11:58pm UTC](https://discuss.elastic.co/t/filebeat-beta1-insane-memory-footprint/61998/5 "2016-10-22T23:58:46Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
