# Filebeat creating multiple threads and consuming system resources

**URL:** <https://discuss.elastic.co/t/filebeat-creating-multiple-threads-and-consuming-system-resources/219484>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 15, 2020, 4:46pm UTC](https://discuss.elastic.co/t/filebeat-creating-multiple-threads-and-consuming-system-resources/219484 "2020-02-15T16:46:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nadia11](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nadia11/32/62767_2.png) [@Nadia11](https://discuss.elastic.co/u/Nadia11)\
**Post date:** [February 15, 2020, 4:46pm UTC](https://discuss.elastic.co/t/filebeat-creating-multiple-threads-and-consuming-system-resources/219484/1 "2020-02-15T16:46:41Z")

</div>

I have enable the filebeat, it started with consuming systems resources and creating multiple threads.  
I installed filebeat on a lunix server and ‘yml’ configuration file is as below. Would you please look into the same and support.

I am using filebeat 6.4.2

###################### Filebeat Configuration #########################

- type: log  
enabled: true  
paths:  
- /applog/logs/log\_MS_202_.log\*

filebeat.config.modules:

# Glob pattern for configuration loading

path: ${path.config}/modules.d/\*.yml

# Set to true to enable config reloading

reload.enabled: false

#================================ General =====================================

#----------------------------- Logstash output --------------------------------  
output.logstash:

# The Logstash hosts

hosts: ["p1osbansr01.btc.com.bh:5044"]

compression\_level: 3  
max\_retries: -1

#================================ Logging =====================================

# Sets log level. The default log level is info.

# Available log levels are: error, warning, info, debug

logging.level: info

# At debug level, you can selectively enable logging only for some components.

# To enable all selectors use ["\*"]. Examples of other selectors are "beat",

# "publish", "service".

logging.selectors: ["\*"]

logging.to\_files: true

logging.files:  
path: /var/log/filebeat  
rotateeverybytes: 10485760 # = 10MB  
keepfiles: 7

filebeat 24780 24779 0 10:10 ? 00:00:17 /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeat -d \* -c /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeat.yml  
filebeat 25190 25180 0 10:15 ? 00:00:00 /bin/sh -c /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeatstart.sh  
filebeat 25191 25190 0 10:15 ? 00:00:15 /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeat -d \* -c /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeat.yml  
filebeat 26722 26706 0 10:20 ? 00:00:00 /bin/sh -c /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeatstart.sh  
filebeat 26723 26722 0 10:20 ? 00:00:11 /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeat -d \* -c /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeat.yml  
filebeat 27507 27498 0 10:25 ? 00:00:00 /bin/sh -c /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeatstart.sh  
filebeat 27508 27507 0 10:25 ? 00:00:10 /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeat -d \* -c /home/filebeat/filebeat-6.4.2-linux-x86\_64/filebeat.yml  
filebeat 28058 28046 0 10:30 ? 00:00:00 /bin/sh -c /home/filebeat/filebeat-6.4.2-linux-x86

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [February 18, 2020, 3:07pm UTC](https://discuss.elastic.co/t/filebeat-creating-multiple-threads-and-consuming-system-resources/219484/2 "2020-02-18T15:07:45Z")

</div>

Could you please format the config file using `</>`? Also, please share the debug logs of Filebeat (`./filebeat -e -d "*"`).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2020, 3:07pm UTC](https://discuss.elastic.co/t/filebeat-creating-multiple-threads-and-consuming-system-resources/219484/3 "2020-03-17T15:07:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
