# High CPU usage docker container running Logstash 2.0

**URL:** <https://discuss.elastic.co/t/high-cpu-usage-docker-container-running-logstash-2-0/35180>\
**Category:** Logstash\
**Created:** [November 20, 2015, 6:34pm UTC](https://discuss.elastic.co/t/high-cpu-usage-docker-container-running-logstash-2-0/35180 "2015-11-20T18:34:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![danwald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danwald/32/6059_2.png) [@danwald](https://discuss.elastic.co/u/danwald)\
**Post date:** [November 20, 2015, 6:34pm UTC](https://discuss.elastic.co/t/high-cpu-usage-docker-container-running-logstash-2-0/35180/1 "2015-11-20T18:34:28Z")

</div>

I am running the official logstash2.0 (using marathon via mesos) docker and the process is using a lot of CPU. Heres what the top on the process and its threads (below).  
The process eventually dies failing to connect to elastic search saying it's not available which isn't the case or it runs out of memory or it gets a GC error even though I have  
`"JAVA_OPTS":"-Xmx12000m -XX:-UseGCOverheadLimit"` set.  
If anyone has any ideas, that would be great?

The logstash pipeline is  
Input: s3  
filters csv, date, mutate  
output: elasticsearch

Part of my input pipe moves the files after processing, but this fails to happen if the process dies. I would think it would move the processed records because I can see them coming into elastic search?  
Cheers,

- danny

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 21, 2015, 5:56am UTC](https://discuss.elastic.co/t/high-cpu-usage-docker-container-running-logstash-2-0/35180/2 "2015-11-21T05:56:58Z")

</div>

> [@danwald](#):
>
> official logstash2.0 (using marathon via mesos) docker

This is an official image provided by Docker, not us 😄

However you should check the LS logs, there may be a problem causing it to not start correctly, and if something like upstart is restarting the process, you can see this sort of behaviour.

---

<div class="post-metadata">

**Author:** ![danwald](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danwald/32/6059_2.png) [@danwald](https://discuss.elastic.co/u/danwald)\
**Post date:** [November 21, 2015, 10:26am UTC](https://discuss.elastic.co/t/high-cpu-usage-docker-container-running-logstash-2-0/35180/3 "2015-11-21T10:26:25Z")

</div>

Warkolm,  
it's actually a job started by marathon, which is a mesos framework that loads the job on a slave. I have provisioned it for 13GB and 12core limits but it still happens.  
However there is light and the end of this tunnel.  
I noticed that `stdout` was also part of the output plugin. I removed that and it has been running fine.  
Thanks for the input.  
I guess this was user error.  
Cheers,

- danny

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:21am UTC](https://discuss.elastic.co/t/high-cpu-usage-docker-container-running-logstash-2-0/35180/4 "2017-07-06T05:21:54Z")

</div>


