# Finetuning CPU usage

**URL:** <https://discuss.elastic.co/t/finetuning-cpu-usage/244129>\
**Category:** Logstash\
**Created:** [August 7, 2020, 7:17am UTC](https://discuss.elastic.co/t/finetuning-cpu-usage/244129 "2020-08-07T07:17:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![evacch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evacch/32/49448_2.png) [@evacch](https://discuss.elastic.co/u/evacch)\
**Post date:** [August 7, 2020, 7:17am UTC](https://discuss.elastic.co/t/finetuning-cpu-usage/244129/1 "2020-08-07T07:17:50Z")

</div>

Hi,

I am new to ELK and I am running ELK in a CentOS 7 environment. I have 4 CPU cores in this machine and with the default configuration of Logstash, the CPU usage is always very high.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a0359234fabd18dff0f4e4c228417d11b549423f.png)

Knowing that running Logstash is I/O intensive and multiline consumes a lot of CPU resource, here below is my Logstash configuration file. May I know how to optimize the CPU utilization for Logstash?

> input {  
> file {  
> path =\> ["java.log"]  
> start\_position =\> "beginning"  
> sincedb\_path =\> "/dev/null"  
> codec =\> multiline {  
> patterns\_dir =\> "/etc/logstash/custom-patterns/custom"  
> pattern =\> "^%{NUMBER20} "  
> negate =\> true  
> what =\> previous  
> }  
> type =\> "xservice"  
> }  
> }
> 
> filter {  
> if [type] == "xservice" {  
> mutate {  
> replace =\> {document\_type =\> "xservice"}  
> gsub =\> ["message", "\n", ""]  
> }
> 
> grok {  
> patterns\_dir =\> "/etc/logstash/custom-patterns/custom"  
> match =\> {"message" =\> "%{JAVALOG}"}  
> }
> 
> date {  
> match =\> ["timestamp","YYYY-MM-dd HH:mm:ss,SSS"]  
> target =\> "@timestamp"  
> remove\_field =\> ["timestamp"]  
> }  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> index =\> "%{document\_type}-%{+YYYY.MM.dd}"  
> }  
> }

Also, it was previously very slow in log ingestion until I made some changes to the pipeline.batch.size, pipeline.batch.delay and JVM heap size, it got better in performance but I am worried with the CPU utilization.

Please help. Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2020, 7:18am UTC](https://discuss.elastic.co/t/finetuning-cpu-usage/244129/2 "2020-09-04T07:18:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
