# High CPU usage with clean Logstash install

**URL:** <https://discuss.elastic.co/t/high-cpu-usage-with-clean-logstash-install/106598>\
**Category:** Logstash\
**Created:** [November 6, 2017, 11:31pm UTC](https://discuss.elastic.co/t/high-cpu-usage-with-clean-logstash-install/106598 "2017-11-06T23:31:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ender](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@Ender](https://discuss.elastic.co/u/Ender)\
**Post date:** [November 6, 2017, 11:31pm UTC](https://discuss.elastic.co/t/high-cpu-usage-with-clean-logstash-install/106598/1 "2017-11-06T23:31:39Z")

</div>

Hi,

I'm new on Elastic Stack but there is a problem with my logstash service.  
Without any configuration (or with a basic configuration), there is a heavy CPU usage when i start logstash, my server hanging:

![logstash_cpu](https://us1.discourse-cdn.com/elastic/original/3X/4/4/442744e09e560e5aa38d080ad36d2b3a7b3e3bbb.PNG)

If i stop logstash, Load Average slow immediatly. I didn't touch any config file, and if i create a conf in conf.d, problem still here.

Versions:  
CentOS Linux release 7.4.1708 (Core)  
Logstash 5.6.3

Any idea?  
Thanks! 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 6, 2017, 11:55pm UTC](https://discuss.elastic.co/t/high-cpu-usage-with-clean-logstash-install/106598/2 "2017-11-06T23:55:54Z")

</div>

What do the Logstash logs show?

---

<div class="post-metadata">

**Author:** ![neuralfraud](https://avatars.discourse-cdn.com/v4/letter/n/7ea924/32.png) [@neuralfraud](https://discuss.elastic.co/u/neuralfraud)\
**Post date:** [November 19, 2017, 7:05am UTC](https://discuss.elastic.co/t/high-cpu-usage-with-clean-logstash-install/106598/3 "2017-11-19T07:05:27Z")

</div>

Same issue, somewhat disappointed that there isn't further activity here, since I too am on a bone-stock clean install of Cent 7 - updated to current and running oracle JVM 8 64-bit (also does the same on OpenJDK 8)

[2017-11-19T02:01:44,837][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"/usr/share/logstash/modules/fb\_apache/configuration"}  
[2017-11-19T02:01:44,840][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"/usr/share/logstash/modules/netflow/configuration"}  
[2017-11-19T02:01:45,077][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2017-11-19T02:01:45,277][INFO][logstash.config.source.local.configpathloader] No config files found in path {:path=\>"/etc/logstash/conf.d/\*.conf"}  
[2017-11-19T02:01:45,355][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

This sequence keeps repeating.

Two worker threads, 200% CPU utilization. doesn't seem right since there's literally NO config, no input, nothing.

---

<div class="post-metadata">

**Author:** ![Tomschi](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@Tomschi](https://discuss.elastic.co/u/Tomschi)\
**Post date:** [November 19, 2017, 4:18pm UTC](https://discuss.elastic.co/t/high-cpu-usage-with-clean-logstash-install/106598/4 "2017-11-19T16:18:09Z")

</div>

I have the same issue and also created a topic [Logstash 6 not working after fresh service install](https://discuss.elastic.co/t/logstash-6-not-working-after-fresh-service-install/108236?u=tomschi)

This behavior also occurs, when running logstash as service in Ubuntu.

---

<div class="post-metadata">

**Author:** ![neuralfraud](https://avatars.discourse-cdn.com/v4/letter/n/7ea924/32.png) [@neuralfraud](https://discuss.elastic.co/u/neuralfraud)\
**Post date:** [November 19, 2017, 6:08pm UTC](https://discuss.elastic.co/t/high-cpu-usage-with-clean-logstash-install/106598/5 "2017-11-19T18:08:51Z")

</div>

Welp, simply enough, you gotta have a pipeline. You can't just have a fresh install and start it up and expect it to run quietly - it constantly checks for something to do and because there's no pipeline, logstash goes into an infinite loop of re-initializing - which consumes the entire CPU allocation.

I created a simple config to tail the /var/log/messages file and shove it into elasticsearch, and because obvious, logstash is running quietly and happily, sending my system log to elasticsearch.

May as well close.

I do think it's kind of strange for it to behave that way - it's not immediately obvious that one should have at least one working pipeline in place for it to just run quietly.

I'm still working through reading the reference docs, there is quite a lot to digest for a noob who has been spoiled by Splunk 😉

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [November 25, 2017, 4:42pm UTC](https://discuss.elastic.co/t/high-cpu-usage-with-clean-logstash-install/106598/6 "2017-11-25T16:42:03Z")

</div>

The high CPU is probably JRuby JIT compiling at startup.

If logstash starts without a pipeline, it exits. Then the service manager notices this and starts it. Until a config is found, this will repeat.

In LS 6 there are many potential sources of configs when none are specified with `-f` or `-e` on the command line.

1. From a module specified in `logstash.yml`
2. From `pipelines.yml`
3. From config defined in `path.config` in `logstash.yml`
4. From config defined in `config.string` in `logstash.yml`
5. From config defined in Elasticsearch via xpack centralised config management -  
see [https://www.elastic.co/guide/en/logstash/6.0/configuring-centralized-pipelines.html](https://www.elastic.co/guide/en/logstash/6.0/configuring-centralized-pipelines.html)

While the service continually restarts, one can fully edit any of the above settings and Logstash will just start working (if the config is found and is valid).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 23, 2017, 4:42pm UTC](https://discuss.elastic.co/t/high-cpu-usage-with-clean-logstash-install/106598/7 "2017-12-23T16:42:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
