# How to configure Logstash pipeline to not OOM-Kill ElasticSearch

**URL:** <https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949>\
**Category:** Logstash\
**Created:** [August 16, 2023, 6:52pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949 "2023-08-16T18:52:02Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![amattice](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amattice/32/124675_2.png) [@amattice](https://discuss.elastic.co/u/amattice)\
**Post date:** [August 16, 2023, 6:52pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949/1 "2023-08-16T18:52:02Z")

</div>

I'm very new here and to the ELK stack in general. I setup an Ubuntu VM in my Azure resource group and installed the latest Elasticsearch,LogStash, and Kibana. I have basic user authentication setup for kibana, and no SSL in http or transport. Essentially my goal is to have 3 of my production VMS sending different log sources to this VM's logstash, process, and display in the dashboard. I wanted to started out simple with winlogbeat, but I've been running into a memory issue I believe? When I just have Elasticsearch and kibana running, it works fine...but when I start up logstash, it practically crashes the whole system, and my elasticsearch ends up exiting because it gets killed by OOM. I'm not sure what steps I should take to further debug this? The VM has 4GB of RAM, which should be plenty for this application no? I'm sorry I'm not really sure what information I need to give for y'all to be able to help me out, but I'll be glad to provide anything you need.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [August 17, 2023, 5:36am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949/2 "2023-08-17T05:36:22Z")

</div>

Hello Anthony,

4GB seems a bit low for your setup:  
By default, Logstash always takes [1GB](https://github.com/elastic/logstash/blob/main/config/jvm.optionshttps://github.com/elastic/logstash/blob/main/config/jvm.options#L6), but you can force it to a certain value by using `-Xms` and `-Xmx` parameters in the `jvm.options`.  
Elasticsearch detects the required memory [dynamically](https://www.elastic.co/guide/en/elasticsearch/reference/current/important-settings.html#heap-size-settings) based on your memory and the roles assigned, but you can force it to a certain value by using `-Xms` and `-Xmx` parameters in the `jvm.options`.  
Kibana works the same as Elasticsearch and [scales with the available memory](https://www.elastic.co/guide/en/kibana/current/production.html#memory), but can be limited using `--max-old-space-size` in the `node.options`.

So, what you can try to do is using the above settings to limit the memory usage and see if the processes are running, but I would say that you need at least 5GB (2GB Elasticsearch, 1GB Logstash, 1GB Kibana, 1GB OS) of RAM to have it running.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [August 17, 2023, 5:50am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949/3 "2023-08-17T05:50:28Z")

</div>

Also you don't need LS for Winlogbeat, and can limit LS to 512 MB.

---

<div class="post-metadata">

**Author:** ![amattice](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amattice/32/124675_2.png) [@amattice](https://discuss.elastic.co/u/amattice)\
**Post date:** [August 17, 2023, 12:52pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949/4 "2023-08-17T12:52:40Z")

</div>

Thanks for your reply! I did a combination of that...I expanding to 8GB of RAM (next available VM size in azure) and I also created an .options file in the jvm.options.d folder as elasticsearch recommends. All that stuff seems to be coming through smoothly! I'm not sure if I did the setup wrong with winlogbeat now...but its like the original setup commands never happened upon first startup. I believe I just did the MSI install on windows. But no template was imported to elasticsearch, and no dashboards were imported either. I get an error when trying to import the dashboards. Should I reinstall it a different way on my windows VMS?

---

<div class="post-metadata">

**Author:** ![amattice](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amattice/32/124675_2.png) [@amattice](https://discuss.elastic.co/u/amattice)\
**Post date:** [August 17, 2023, 12:53pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949/5 "2023-08-17T12:53:42Z")

</div>

Very true...I only went with LogStash because in the end I will be using FileBeat, WinLogBeat, and another one for SQL on 3 different VMS. Thought it would just be better to route everything through logstash. If that is not the case I'm willing to scrap that and do the ingestion nodes directly through elasticsearch/kibana.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [August 18, 2023, 5:50am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949/6 "2023-08-18T05:50:46Z")

</div>

> I get an error when trying to import the dashboards. Should I reinstall it a different way on my windows VMS?

Which error do you get?

---

<div class="post-metadata">

**Author:** ![amattice](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amattice/32/124675_2.png) [@amattice](https://discuss.elastic.co/u/amattice)\
**Post date:** [August 18, 2023, 12:57pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949/7 "2023-08-18T12:57:51Z")

</div>

I get

`Exiting: Error connecting to Kibana: fail to get the Kibana version: fail to parse kibana version(): passed version is not semvar:`

When I visit http /api/status in my browser on the box I see

`{"status":{"overall":{"level":"available"}}}`

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [August 21, 2023, 5:18am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949/8 "2023-08-21T05:18:59Z")

</div>

Can you please check which versions of the products you use? Maybe there is an incompatibility between the Kibana and the Beat version: [Support Matrix | Elastic](https://www.elastic.co/support/matrix#matrix_compatibility)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2023, 5:19am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949/9 "2023-09-18T05:19:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
