# High cpu and Beats input: the pipeline is blocked, temporary refusing new connection

**URL:** <https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270>\
**Category:** Logstash\
**Created:** [July 12, 2016, 8:38am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270 "2016-07-12T08:38:19Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![xiongzhichaoelk](https://avatars.discourse-cdn.com/v4/letter/x/3d9bf3/32.png) [@xiongzhichaoelk](https://discuss.elastic.co/u/xiongzhichaoelk)\
**Post date:** [July 12, 2016, 8:38am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/1 "2016-07-12T08:38:19Z")

</div>

when I start logstash after about 5 minutes ,the log 🙂

 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/d09cc682720a729038db725169aaa0124b2b470a.png)  
the cpu 100% 🙂 ![](https://us1.discourse-cdn.com/elastic/original/2X/6/692a4a9c5b7b74c57148a33ab3672665ff2d26fa.png)

 ![](https://us1.discourse-cdn.com/elastic/original/2X/6/66173b1b7ba83952dedad836b0d8b7fe354d22ea.png)

the config:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0d9d9e17035a1181be2cc9f5e6c116f727d7993a.png)

the ela is normal:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/f2bb195283c8d1c75b69c0dc1e73cf4bd6d38591.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 12, 2016, 8:52am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/2 "2016-07-12T08:52:21Z")

</div>

Which Java process is hogging the CPU, Logstash or Elasticsearch?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 12, 2016, 11:27pm UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/3 "2016-07-12T23:27:31Z")

</div>

Please don't post pictures of text, they are difficult to read and some people may not be even able to see them.

---

<div class="post-metadata">

**Author:** ![xiongzhichaoelk](https://avatars.discourse-cdn.com/v4/letter/x/3d9bf3/32.png) [@xiongzhichaoelk](https://discuss.elastic.co/u/xiongzhichaoelk)\
**Post date:** [July 13, 2016, 5:28pm UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/4 "2016-07-13T17:28:18Z")

</div>

logstash ,it published on a server alone  
there are eight worker processes hogging the cpu:  
%cup command  
100.2 [main] \> worker0  
100.2 [main] \> worker2  
100.2 [main] \> worker5  
99.9 [main] \> worker1  
99.9 [main] \> worker3  
99.9 [main] \> worker4  
99.9 [main] \> worker6  
99.9 [main] \> worker7

Logstah:insertToolong queue and the pipeline is blocked,temporary refusing new connection

the kopf of elasticsearch :  
load average: 0.0  
cpu% : 2.0  
heap useage % : 44.0

---

<div class="post-metadata">

**Author:** ![xiongzhichaoelk](https://avatars.discourse-cdn.com/v4/letter/x/3d9bf3/32.png) [@xiongzhichaoelk](https://discuss.elastic.co/u/xiongzhichaoelk)\
**Post date:** [July 14, 2016, 11:26am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/5 "2016-07-14T11:26:14Z")

</div>

I find the grok filter lead to the high cpu by check out the jstack:  
at rubyjit.LogStash::Filters::Grok$$filter\_428454220f2f91b7ec1ad9e019332db0555035611028566121.block\_0$RUBY$ **file** (/usr/local/elk/logstash-2.3.3/vendor/bundle/jruby/1.9/gems/logstash-filter-grok-2.0.5/lib/logstash/filters/grok.rb:279)  
at rubyjit$LogStash::Filters::Grok$$filter\_428454220f2f91b7ec1ad9e019332db0555035611028566121$block\_0$RUBY$ **file**.call(rubyjit$LogStash::Filters::Grok$$filter\_428454220f2f91b7ec1ad9e019332db0555035611028566121$block\_0$RUBY$ **file** )

my config:  
input {  
beats {  
port =\> 5044  
type =\> "xzb\_logs"  
congestion\_threshold =\> 10  
}  
}  
filter{  
if[type] == "xzb\_logs"{  
grok{  
match =\>{  
message =\> "(?[0-9]{4}-[0-9]{2}-[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2} (?:Z|+-(?::?(?:[0-5][0-9])))) (?[\w]_)/(?[\w]_) (?[\w]_) (?[\d\w]+-[\d\w]+)/(?\w+(.[\w]+)_) %{WORD:LOGLEVEL}/(?[^:]_):(?[\s\S]_)"  
}  
}  
date{  
match =\> ["TIME","yyyy-MM-dd HH:mm:ss Z"]

```
            }
    }

```

}  
output {  
elasticsearch {  
hosts =\> ["10.10.45.45:9200"]  
index =\> "logstash-%{type}-%{+YYYY.MM.dd}"  
document\_type =\> "%{type}"  
workers =\> 1  
flush\_size =\> 200  
}  
}

the log format:  
[TIME] [BUSINESS/PLATFORM] [DEVID] [PID-TID/PACKAGE] [LOGLEVEL]/[TAG]:[TEXT]  
example:  
2016-07-10 00:42:11 +0800 xzbApp/android x8dcc5070ff395e1 20551-1/com.xunlei.timealbum I/XZBDeviceManager: requestDeviceList frefXZBDeviceManager Init

---

<div class="post-metadata">

**Author:** ![ally](https://avatars.discourse-cdn.com/v4/letter/a/8edcca/32.png) [@ally](https://discuss.elastic.co/u/ally)\
**Post date:** [July 25, 2016, 8:11am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/6 "2016-07-25T08:11:54Z")

</div>

How did you notice the grok filter is maxing out your cpu??

---

<div class="post-metadata">

**Author:** ![rashthedude](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@rashthedude](https://discuss.elastic.co/u/rashthedude)\
**Post date:** [December 8, 2016, 9:14am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/7 "2016-12-08T09:14:59Z")

</div>

We seem to be having the same problem over here as well. Logstash is hogging the CPU. If grok is responsible for that are there any work-arounds?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 8, 2016, 10:26am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/8 "2016-12-08T10:26:20Z")

</div>

Depending on how complex your logs are, you may want to consider the [new dissect filter](https://www.elastic.co/blog/logstash-dude-wheres-my-chainsaw-i-need-to-dissect-my-logs).

---

<div class="post-metadata">

**Author:** ![rashthedude](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@rashthedude](https://discuss.elastic.co/u/rashthedude)\
**Post date:** [December 8, 2016, 10:54am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/9 "2016-12-08T10:54:53Z")

</div>

@Christian_Dahlqvist thanks for the swift reply. Here's our config file, not sure if it's complex or not:

input {  
2 beats {  
3 port =\> 5000  
4 host =\> "xx.xx.xxx.xx"  
5 type =\> "smpp"  
6 ssl =\> true  
7 ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
8 ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
9 congestion\_threshold =\> "50"  
10 }  
11 }  
12 filter {  
13 if [type] == "smpp" {  
14 grok {  
15 match =\> { "message" =\> "%{DATESTAMP:flow\_date\_time}%{SPACE}%{NOTSPACE:connection}%{SPACE}[from:%{NUMBER:sendfrom}]%{SPACE}[to:%{NUMBER:sendto}\]%{SPACE}[msg:%{NUMBER:msgno}🆔%{NUMBER:msgid}%{SPACE}sub:%{NUMBER:sub}%{SPACE}%{NOTSPACE:dlvrdstatus}%{SPACE}submit%{SPACE}date:%{NUMBER:submitdate}% {SPACE}done%{SPACE}date:%{NUMBER:donedate}%{SPACE}stat:%{WORD:status}%{SPACE}err:%{NUMBER:err}%{SPACE}\Text:-]"  
16 }  
17 break\_on\_match =\> false  
18 match =\> { "message" =\> "%{DATESTAMP:flow\_date\_time}%{SPACE}[%{NOTSPACE:connection}]%{SPACE}[from:%{NUMBER:sendfrom}]%{SPACE}[to:%{NUMBER:send to}]%{SPACE}[msg:%{GREEDYDATA:msg}]"  
19 }  
20 }  
21 }  
22 if [type] == "smpp" { if [msgno] == "103" { mutate { add\_tag =\> "dn" } } }  
23 if [type] == "smpp" { if [msgno] != "103" { mutate { add\_tag =\> "mt" } } }  
24 }  
25 output {  
26 elasticsearch {  
27 hosts =\> ["[something-something-b33oicrd2ovp7gmu4maowywe5e.eu-west-1.es.amazonaws.com:80](http://something-something-b33oicrd2ovp7gmu4maowywe5e.eu-west-1.es.amazonaws.com:80)"]  
28 }  
29 }

---

<div class="post-metadata">

**Author:** ![rashthedude](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@rashthedude](https://discuss.elastic.co/u/rashthedude)\
**Post date:** [December 8, 2016, 5:15pm UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/10 "2016-12-08T17:15:39Z")

</div>

The reason I can't use the dissect methods is due to the fact we are still using Logstash version 2.2.4 @Christian_Dahlqvist

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 8, 2016, 5:41pm UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/11 "2016-12-08T17:41:32Z")

</div>

Logstash 5.x should be backwards compatible with Elasticsearch 2.x, so it may be worth upgrading. I have seen reports of significant performance improvements, but this naturally varies depending on the data.

---

<div class="post-metadata">

**Author:** ![rashthedude](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@rashthedude](https://discuss.elastic.co/u/rashthedude)\
**Post date:** [December 9, 2016, 10:20am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/12 "2016-12-09T10:20:45Z")

</div>

@Christian_Dahlqvist we are currently using the AWS elasticsearch service which at this time only supports Elasticsearch 1.5 and 2.3 so not quite sure if we can upgrade.

---

<div class="post-metadata">

**Author:** ![rashthedude](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@rashthedude](https://discuss.elastic.co/u/rashthedude)\
**Post date:** [December 9, 2016, 10:57am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/13 "2016-12-09T10:57:01Z")

</div>

Even removing the grok filters and restarting logstash does not seem to work. Looking into logstash.log only shows the message that SIGTERM was received. I'm confused at this stage.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:29am UTC](https://discuss.elastic.co/t/high-cpu-and-beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/55270/14 "2017-07-06T04:29:56Z")

</div>


