# Java Heap Space error OutOfMemoryError Logstash

**URL:** <https://discuss.elastic.co/t/java-heap-space-error-outofmemoryerror-logstash/198899>\
**Category:** Logstash\
**Created:** [September 10, 2019, 12:45pm UTC](https://discuss.elastic.co/t/java-heap-space-error-outofmemoryerror-logstash/198899 "2019-09-10T12:45:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [September 10, 2019, 12:45pm UTC](https://discuss.elastic.co/t/java-heap-space-error-outofmemoryerror-logstash/198899/1 "2019-09-10T12:45:45Z")

</div>

I am getting an error Logstash - java.lang.OutOfMemoryError: Java heap space. However, I have changed the heap memory in the jvm.options file from 1g to 2g to 8g to 10g. I am still getting the same errors though. How can I find out how much heap space I need to use or am I supposed to make a different change in this or another file elsewhere.

For the error in the /var/log/elasticsearch I am getting a org.elasticsearch.action.search.SearchPhaseExecutionException: all shards failed

The error also comes about after a while when the logstash has already been run successfully.

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [September 10, 2019, 12:46pm UTC](https://discuss.elastic.co/t/java-heap-space-error-outofmemoryerror-logstash/198899/2 "2019-09-10T12:46:10Z")

</div>

Error produced from running config file:

java.lang.OutOfMemoryError: Java heap space  
Dumping heap to java\_pid110004.hprof ...  
Heap dump file created [1285291394 bytes in 9.087 secs]  
warning: thread "[main]\>worker0" terminated with exception (report\_on\_exception is true):  
java.lang.OutOfMemoryError: Java heap space  
at java.nio.HeapCharBuffer.(HeapCharBuffer.java:57)  
at java.nio.CharBuffer.allocate(CharBuffer.java:335)  
at java.nio.charset.CharsetDecoder.decode(CharsetDecoder.java:795)  
at java.nio.charset.Charset.decode(Charset.java:807)  
at org.jruby.RubyEncoding.decodeUTF8(RubyEncoding.java:269)  
at org.jruby.runtime.Helpers.decodeByteList(Helpers.java:2439)  
at org.jruby.RubyString.decodeString(RubyString.java:797)  
at org.jruby.RubyString.toJava(RubyString.java:6221)  
at org.jruby.java.invokers.ConstructorInvoker.call(ConstructorInvoker.java:98)  
at org.jruby.java.invokers.ConstructorInvoker.call(ConstructorInvoker.java:195)  
at org.jruby.runtime.callsite.CachingCallSite.cacheAndCall(CachingCallSite.java:378)  
at org.jruby.runtime.callsite.CachingCallSite.call(CachingCallSite.java:213)  
at org.jruby.java.proxies.ConcreteJavaProxy$InitializeMethod.call(ConcreteJavaProxy.java:60)  
at org.jruby.runtime.callsite.CachingCallSite.call(CachingCallSite.java:211)  
at org.jruby.RubyClass.newInstance(RubyClass.java:997)  
at org.jruby.RubyClass$INVOKER$i$newInstance.call(RubyClass$INVOKER$i$newInstance.gen)  
at org.jruby.internal.runtime.methods.JavaMethod$JavaMethodZeroOrOneOrTwoOrNBlock.call(JavaMethod.java:353)  
at org.jruby.java.proxies.ConcreteJavaProxy$NewMethod.call(ConcreteJavaProxy.java:165)  
at java.lang.invoke.LambdaForm$DMH/1089407736.invokeVirtual\_L7\_L(LambdaForm$DMH)  
at java.lang.invoke.LambdaForm$BMH/1063494931.reinvoke(LambdaForm$BMH)  
at java.lang.invoke.LambdaForm$MH/1259769769.delegate(LambdaForm$MH)  
at java.lang.invoke.LambdaForm$MH/296954388.guard(LambdaForm$MH)  
at java.lang.invoke.LambdaForm$MH/1259769769.delegate(LambdaForm$MH)  
at java.lang.invoke.LambdaForm$MH/296954388.guard(LambdaForm$MH)  
at java.lang.invoke.LambdaForm$MH/621502043.linkToCallSite(LambdaForm$MH)  
at usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.manticore\_minus\_0\_dot\_6\_dot\_4\_minus\_java.lib.manticore.client.RUBY$method$request\_from\_options$0(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.6.4-java/lib/manticore/client.rb:471)  
at java.lang.invoke.LambdaForm$DMH/1436901839.invokeStatic\_L9\_L(LambdaForm$DMH)  
at java.lang.invoke.LambdaForm$BMH/77334939.reinvoke(LambdaForm$BMH)  
at java.lang.invoke.LambdaForm$MH/589835301.delegate(LambdaForm$MH)  
at java.lang.invoke.LambdaForm$MH/505567264.guard(LambdaForm$MH)  
at java.lang.invoke.LambdaForm$MH/589835301.delegate(LambdaForm$MH)  
at java.lang.invoke.LambdaForm$MH/505567264.guard(LambdaForm$MH)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 10, 2019, 1:22pm UTC](https://discuss.elastic.co/t/java-heap-space-error-outofmemoryerror-logstash/198899/3 "2019-09-10T13:22:34Z")

</div>

For you to get a 1.2 GB heap dump after an OOM in an 8 or 10 GB heap would be unusual. After the OOM a full GC is run before the dump is written, which means there were multiple GB of garbage on the heap when the OOM occurred. If that happened when using the default GC it would suggest an extremely fast object allocation and expiration rate. (It could also be allocation of a large object in a badly fragmented heap, but that would be even more unusual in my experience.)

No matter. To find the problem you should take a look at the heap dump in a tool like [MAT](https://www.eclipse.org/mat/). If you find yourself spending more than a minute trying to work out what is using all the memory then give up. It should be front and centre on the main page.

The stack trace shows it is in manticore, which is the http client that logstash uses. Are you using an http or elasticsearch input or an http filter? What does the configuration look like.

If that is the current code (and I think 0.6.4 is current) then it is [building the body](https://github.com/cheald/manticore/blob/5a2fb766cb6f96ff7b1082381d65f15f6235dbb5/lib/manticore/client.rb#L471) of the request.

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [September 10, 2019, 1:41pm UTC](https://discuss.elastic.co/t/java-heap-space-error-outofmemoryerror-logstash/198899/4 "2019-09-10T13:41:54Z")

</div>

> input {  
> file {  
> path =\> "/csvDirectory/\*.csv"  
> start\_position =\> "beginning"  
> sincedb\_path =\> "/dev/null"  
> }  
> }  
> filter {  
> csv {  
> separator =\> " "  
> columns =\> ["26 column names"]  
> }  
> mutate {  
> split =\> { "path\_column\_name" =\> " (View)$" }  
> split =\> { "variant" =\> "," }  
> split =\> { "module" =\> "," }  
> strip =\> ["linkid","itemrev","uid"]  
> remove\_field =\> "[message]"  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> ["hostname:9200"]  
> index =\> "index\_name"  
> document\_id =\> "%{8 different fields}"  
> }  
> }

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 10, 2019, 1:43pm UTC](https://discuss.elastic.co/t/java-heap-space-error-outofmemoryerror-logstash/198899/5 "2019-09-10T13:43:05Z")

</div>

Believe it or not I had a lot of trouble with out of memory.  
turn out that all started when we remove all the swap space off.

we were new to this and was just following what elk suggest.

after turnning swapon back it all go away.

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [September 10, 2019, 6:51pm UTC](https://discuss.elastic.co/t/java-heap-space-error-outofmemoryerror-logstash/198899/6 "2019-09-10T18:51:45Z")

</div>

The issue could be that it is pulling in many csv files all of which are very large in size, up to 5gb for one single csv file.

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [September 18, 2019, 6:53pm UTC](https://discuss.elastic.co/t/java-heap-space-error-outofmemoryerror-logstash/198899/7 "2019-09-18T18:53:32Z")

</div>

It seems to have been fixed by increasing the heap size on Logstash. I was only increasing on the Elastic servers. It went over my head to increase the heap size of the logstash server instead. @Badger

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 16, 2019, 6:53pm UTC](https://discuss.elastic.co/t/java-heap-space-error-outofmemoryerror-logstash/198899/8 "2019-10-16T18:53:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
