# Filebeat get big log file

**URL:** <https://discuss.elastic.co/t/filebeat-get-big-log-file/49736>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 11, 2016, 8:26am UTC](https://discuss.elastic.co/t/filebeat-get-big-log-file/49736 "2016-05-11T08:26:41Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 11, 2016, 2:13pm UTC](https://discuss.elastic.co/t/filebeat-get-big-log-file/49736/2 "2016-05-11T14:13:47Z")

</div>

How can you tell logstash performance is great?

There are a many factors regarding filebeat performance. Just sending files to /dev/null on physical machine I was able to process like 95k eps. filebeat throughput depends on disk IO (unless files still buffered by OS caches) and downstream performance. E.g. if sending directly to elasticsearch indexing performance in elasticsearch. If sending to logstash throughput depends on processing time within logstash + performance even more downstream. This is due the outputs generating back-pressure if they can not keep up slowing down event generation in filebeat (as we don't want to drop any events).

somewhat related:

- [Filebeat sending data to Logstash seems too slow](https://discuss.elastic.co/t/filebeat-sending-data-to-logstash-seems-too-slow/37596/9)
- [Filebeat sending data to Logstash seems too slow](https://discuss.elastic.co/t/filebeat-sending-data-to-logstash-seems-too-slow/37596/13)

The second link includes some tips to figure out filebeat throughput to /dev/null and to logstash.

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-get-big-log-file/49736)._
