# Filebeat CPU usage 400%+

**URL:** <https://discuss.elastic.co/t/filebeat-cpu-usage-400/116095>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 18, 2018, 3:37pm UTC](https://discuss.elastic.co/t/filebeat-cpu-usage-400/116095 "2018-01-18T15:37:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [January 18, 2018, 3:37pm UTC](https://discuss.elastic.co/t/filebeat-cpu-usage-400/116095/1 "2018-01-18T15:37:20Z")

</div>

Good Morning,

I have installed and started my filebeat(5.5) agent on a set of servers and I am seeing a very high CPU usage by Filebeat. I recently added the stanzas max\_proc: 2 & scan\_frequency: 30s because I read on another post that this would help, but It has not.

Thanks.

My configs are as follows:

```auto
 ###################### Filebeat Configuration Example #########################

# This file is an example configuration file highlighting only the most common
# options. The filebeat.full.yml file from the same directory contains all the
# supported options with more comments. You can use it as a reference.
#
# You can find the full configuration reference here:
# https://www.elastic.co/guide/en/beats/filebeat/index.html

#=========================== Filebeat prospectors =============================

filebeat.prospectors:

# Each - is a prospector. Most options can be set at the prospector level, so
# you can use different prospectors for various configurations.
# Below are the prospector specific configurations.

  # Paths that should be crawled and fetched. Glob based paths.

- input_type: log
  paths:
  - /some/logs/path/*.log
  exclude_files: ['.fish.log$']
  close_inactive: 10m 
  max_proc: 2 
  scan_frequency: 30s 
  multiline.pattern: '^[0-9]{2}:[0-9]{2}:[0-9]{2}.[0-9]{3}' 
  multiline.negate: true 
  multiline.match: after 
  fields_under_root: true 
  fields: 
    service: my_service 
 
 
- input_type: log
  paths:
  - /some/logs/path/*.log
  exclude_files: ['.fish.log$']
  close_inactive: 10m 
  max_proc: 2 
  scan_frequency: 30s 
  multiline.pattern: '^[0-9]{2}:[0-9]{2}:[0-9]{2}.[0-9]{3}' 
  multiline.negate: true 
  multiline.match: after 
  fields_under_root: true 
  fields: 
    service: my_service

```

Filebeat.yml

```auto
 #=========================== Filebeat prospectors ==============================

filebeat:
  prospectors: []
  
  config_dir: "/my/log/path"
  
#================================= General =====================================

# The name of the shipper that publishes the network data. It can be used to group
# all the transactions sent by a single shipper in the web interface.
#name:

#tags: ["service-X", "web-tier"]

#fields:
# AppID: 

#================================= Outputs =====================================

#------------------------------- File output -----------------------------------
#output.file:
# path: "/var/filebeat/data"
# filename: logdata
# rotate_every_kb: 10000
# number_of_files: 3

#----------------------------- Kafka output --------------------------------
output.kafka:
  # initial brokers for reading cluster metadata
    hosts: ["SET of HOSTS"]
  #

  # message topic selection + partitioning
# topic: "PR106659-OMH0-DEV-test01"
    topic: "MY_TOPIC"
    client_id: ClientA
#
   
# partition.round_robin:
# reachable_only: false

# required_acks: 1
# compression: gzip
# max_message_bytes: 1000000
  
#--------------------------- Elasticsearch output ------------------------------
#output.elasticsearch
# hosts: ["localhost:9200"]

  # Optional protocol and basic auth credentials
  #protocol: "https"
  #username: "elastic"
  #password: ""
  
#================================= Logging =====================================

# Sets log level. The default log level is info.
# Available log levels are: critical, error, warning, info, debug
logging.level: info

# At debug level, you can selectively enable logging only for some components.
# To enable all selectors use ["*"]. Examples of other selectors are "beat",
# "publish", "service".
#logging.selectors: ["*"]

```

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 18, 2018, 3:47pm UTC](https://discuss.elastic.co/t/filebeat-cpu-usage-400/116095/2 "2018-01-18T15:47:43Z")

</div>

Could you please share the output of `filebeat -e -d "*"`?

---

<div class="post-metadata">

**Author:** ![GaryHuang](https://avatars.discourse-cdn.com/v4/letter/g/51bf81/32.png) [@GaryHuang](https://discuss.elastic.co/u/GaryHuang)\
**Post date:** [January 19, 2018, 8:10am UTC](https://discuss.elastic.co/t/filebeat-cpu-usage-400/116095/3 "2018-01-19T08:10:39Z")

</div>

U should set "max\_procs: 2" in filebeat.yml, not the prospectors configuration. And it's not "max\_proc"

---

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [January 19, 2018, 8:17pm UTC](https://discuss.elastic.co/t/filebeat-cpu-usage-400/116095/4 "2018-01-19T20:17:04Z")

</div>

@GaryHuang,

Thanks for catching that typo. We went ahead and added it to filebeat.yml and updated the typo.

@kvch,

We will run this and see what the output is. Thanks.

---

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [February 1, 2018, 5:48pm UTC](https://discuss.elastic.co/t/filebeat-cpu-usage-400/116095/5 "2018-02-01T17:48:44Z")

</div>

@kvch,

Is that the filebeat start command? I have seen ./filebeat -c filebeat.yml -e -d "\*" . Is that what you want me to run?

Thanks

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [February 1, 2018, 6:18pm UTC](https://discuss.elastic.co/t/filebeat-cpu-usage-400/116095/6 "2018-02-01T18:18:45Z")

</div>

Yes, it is.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2018, 6:19pm UTC](https://discuss.elastic.co/t/filebeat-cpu-usage-400/116095/7 "2018-03-01T18:19:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
