# High memory usage of Metricbeat in Kubernetes

**URL:** <https://discuss.elastic.co/t/high-memory-usage-of-metricbeat-in-kubernetes/320784>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [December 8, 2022, 12:24pm UTC](https://discuss.elastic.co/t/high-memory-usage-of-metricbeat-in-kubernetes/320784 "2022-12-08T12:24:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![beatman](https://avatars.discourse-cdn.com/v4/letter/b/67e7ee/32.png) [@beatman](https://discuss.elastic.co/u/beatman)\
**Post date:** [December 8, 2022, 12:24pm UTC](https://discuss.elastic.co/t/high-memory-usage-of-metricbeat-in-kubernetes/320784/1 "2022-12-08T12:24:02Z")

</div>

Hi,

Continuing the discussion from [High memory usage of Metricbeat in Kubernetes](https://discuss.elastic.co/t/high-memory-usage-of-metricbeat-in-kubernetes/301961):

I'm facing exactly the same problem with metricbeat consuming memory until it gets OOM-killed.  
This happens on all three k8s clusters I'm running metricbeat on. I'm using version 7.17.  
I also tried to run a dedicated metricbeat deployment for kube-state-metrics but it has no effect.  
Actually, the KSM metricbeat deployment gets OOM-killed even faster than the other ones.  
It usually takes a couple of hours then metricbeat gets OOM-killed..

I've set the resources.limits.memory to 5Gi, which is extremely high in my opinion.

Here is the configuration of the metricbeat DaemonSet as used in my self-created helm chart:

```auto
---
apiVersion: v1
kind: ConfigMap
metadata:
  name: metricbeat-daemonset-config
  labels:
    {{- include "k8s-beats-monitoring.labels" . | nindent 4 }}
data:
  metricbeat.yml: |-
    monitoring:
      enabled: true
      cluster_uuid: "{{ .Values.elasticsearch.uuid }}"
      elasticsearch:
        hosts: {{ .Values.elasticsearch.hosts | toStrings }}
        username: ${ELASTICSEARCH_USERNAME}
        password: ${ELASTICSEARCH_PASSWORD}
        ssl.certificate_authorities: ["{{ .Values.elasticsearch.certPath }}/ca.crt"]
    metricbeat.config.modules:
      # Mounted `metricbeat-daemonset-modules` configmap:
      path: ${path.config}/modules.d/*.yml
      # Reload module configs as they change:
      reload.enabled: false

    metricbeat.autodiscover:
      providers:
        # To enable hints based autodiscover uncomment this:
        - type: kubernetes
          host: ${NODE_NAME}
          hints.enabled: true

    processors:
      - add_fields:
         target: kubernetes
         fields:
            cluster:
               name: "{{ .Values.kubernetes.cluster.name }}"
      - add_kubernetes_metadata:
      - add_host_metadata:
         cache.ttl: 5m
         geo:
           name: {{ .Values.kubernetes.cluster.name }}
      
    logging.level: warning

    cloud.id: ${ELASTIC_CLOUD_ID}
    cloud.auth: ${ELASTIC_CLOUD_AUTH}

    output.elasticsearch:
      hosts: {{ .Values.elasticsearch.hosts | toStrings }}
      loadbalance: true
      worker: 1
      username: ${ELASTICSEARCH_USERNAME}
      password: ${ELASTICSEARCH_PASSWORD}
      ssl:
         certificate_authorities: ["{{ .Values.elasticsearch.certPath }}/ca.crt"]
---
apiVersion: v1
kind: ConfigMap
metadata:
  name: metricbeat-daemonset-modules
  labels:
    {{- include "k8s-beats-monitoring.labels" . | nindent 4 }}
data:
  system.yml: |-
    - module: system
      period: 10s
      metricsets:
        - cpu
        - load
        - memory
        - network
        - process
        - process_summary
        #- core
        #- diskio
        #- socket
      processes: ['.*']
      process.include_top_n:
        by_cpu: 5 # include top 5 processes by CPU
        by_memory: 5 # include top 5 processes by memory

    - module: system
      period: 1m
      metricsets:
        - filesystem
        - fsstat
      processors:
      - drop_event.when.regexp:
          system.filesystem.mount_point: '^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)'
  kubernetes.yml: |-
    - module: kubernetes
      metricsets:
        - node
        - system
        - pod
        - container
        - volume
      period: 10s
      host: ${NODE_NAME}
      hosts: ["https://${NODE_NAME}:10250"]
      bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
      ssl.verification_mode: "none"
      add_metadata: true
    - module: kubernetes
      metricsets:
        - proxy
      period: 10s
      host: ${NODE_NAME}
      hosts: ["localhost:10249"]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 5, 2023, 2:24pm UTC](https://discuss.elastic.co/t/high-memory-usage-of-metricbeat-in-kubernetes/320784/2 "2023-01-05T14:24:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
