# Improve logstash starting time?

**URL:** <https://discuss.elastic.co/t/improve-logstash-starting-time/103016>\
**Category:** Logstash\
**Created:** [October 6, 2017, 1:33pm UTC](https://discuss.elastic.co/t/improve-logstash-starting-time/103016 "2017-10-06T13:33:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [October 6, 2017, 1:33pm UTC](https://discuss.elastic.co/t/improve-logstash-starting-time/103016/1 "2017-10-06T13:33:05Z")

</div>

Hi,

I know, it is not the hardware logstash is designed for, but hopefully you have some idea which might help me.

I am running a nextcloud instance an would like to visualize server's logs (nextcloud, apache, metrics) in kibana. I don't expect much events since it is only used by a few users.  
It runs on an odroid xu4 (arm) with arch linux.  
You can compare the performance with a fast atom processor, 2 GB memory.

I managed to get elasticsearch, kibana and beats running. startup takes a bit longer than on an ordinary x86 server, but it seems to work so far.  
But with logstash I am struggling.

After starting it takes now 20 minutes to start - and it is not finished yet.  
Any Idea how I can speed it up? I do not use any encryption between logstash and elasticsearch. I read, that there may be some entropy issues which might slow down the logstash start.

haveged is already running on the server.

`cat /proc/sys/kernel/random/entropy_avail`  
gives back values about 3k.

the current logstash log shows:

```
[2017-10-06T12:59:37,349][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"fb_apache", :directory=>"/data/elastic/logstash/current/modules/fb_apache/configuration"}
[2017-10-06T12:59:37,385][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/data/elastic/logstash/current/modules/netflow/configuration"}
[2017-10-06T13:20:06,097][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"fb_apache", :directory=>"/data/elastic/logstash/current/modules/fb_apache/configuration"}
[2017-10-06T13:20:06,134][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/data/elastic/logstash/current/modules/netflow/configuration"}

```

Using elastic stack 5.6.2 with openjdk 8.

Any ideas for speeding it up is apreciated.  
Regards, Andreas

---

<div class="post-metadata">

**Author:** ![jakelandis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakelandis/32/36163_2.png) [@jakelandis](https://discuss.elastic.co/u/jakelandis)\
**Post date:** [October 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/improve-logstash-starting-time/103016/2 "2017-10-06T13:44:51Z")

</div>

Hi @asp,

You are correct about the entropy issues and startup times.

The issue is [https://github.com/elastic/logstash/issues/6117](https://github.com/elastic/logstash/issues/6117) and was fixed here: [https://github.com/elastic/logstash/commit/50cbaf4bf0205af278651208134467a4a23dcee8](https://github.com/elastic/logstash/commit/50cbaf4bf0205af278651208134467a4a23dcee8)

...but we just noticed that changed did NOT make it into release packages (rpm, deb). That issue is here: [https://github.com/elastic/logstash/issues/8427](https://github.com/elastic/logstash/issues/8427) (not fixed yet)

To fix this you can add the this to the bottom of your jvm.options.

```auto
# Entropy source for randomness
-Djava.security.egd=file:/dev/urandom

```

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [October 6, 2017, 3:13pm UTC](https://discuss.elastic.co/t/improve-logstash-starting-time/103016/3 "2017-10-06T15:13:14Z")

</div>

i will try. I took the tar.gz file for manual installation btw.

Update: it is already set there.  
might it be improved when setting it to /dev/random  
?

Or any other things which might help to hunt the problem down? I doubt that is just the performance of the arm processor, because running a linux vm on atom processor is much faster and both cpu's have about the same performance.

---

<div class="post-metadata">

**Author:** ![jakelandis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakelandis/32/36163_2.png) [@jakelandis](https://discuss.elastic.co/u/jakelandis)\
**Post date:** [October 6, 2017, 4:11pm UTC](https://discuss.elastic.co/t/improve-logstash-starting-time/103016/4 "2017-10-06T16:11:51Z")

</div>

I wonder if it isn't picking those jvm options then ? /dev/urandom should be non-blocking.

Try looking at the process, it should be an command line argument:  
For example:

```auto
ps aux | grep logstash

```

```auto
 -Djava.awt.headless=true -Dfile.encoding=UTF-8 -XX:+HeapDumpOnOutOfMemoryError -Djava.security.egd=file:/dev/urandom -Xmx1g -Xms256m -Xss2048k -Djffi.boot.library.path=/usr/share/logstash/vendor/jruby/lib/jni -Xbootclasspath/a:/usr/share/logstash/vendor/jruby/lib/jruby.jar -classpath : -Djruby.home=/usr/share/logstash/vendor/jruby -Djruby.lib=/usr/share/logstash/vendor/jruby/lib -Djruby.script=jruby -Djruby.shell=/bin/sh org.jruby.Main /usr/share/logstash/lib/bootstrap/environment.rb logstash/runner.rb --path.settings /etc/logstash

```

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [October 6, 2017, 4:21pm UTC](https://discuss.elastic.co/t/improve-logstash-starting-time/103016/5 "2017-10-06T16:21:45Z")

</div>

I tried to use oracle jdk instead of openjdk.  
Now it starts in less than a minute.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2017, 4:22pm UTC](https://discuss.elastic.co/t/improve-logstash-starting-time/103016/6 "2017-11-03T16:22:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
