# Limit logstash 7.5 memory usage

**URL:** <https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556>\
**Category:** Logstash\
**Created:** [May 12, 2022, 10:36am UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556 "2022-05-12T10:36:30Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![smm](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@smm](https://discuss.elastic.co/u/smm)\
**Post date:** [May 12, 2022, 10:36am UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/1 "2022-05-12T10:36:30Z")

</div>

Hi there,  
is there a way to limit memory consumption of logstash 7.5? In our case logstash 'eats up' all the memory so that Elasticsearch itself gets killed on the same host (OOM killer).  
From 7.8 onwards a possibility is there:

> **[JVM settings | Logstash Reference \[7.8\] | Elastic](https://www.elastic.co/guide/en/logstash/7.8/jvm-settings.html)**

but it is not documented for lower versions.  
Thanks for any idea!

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 12, 2022, 11:10am UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/2 "2022-05-12T11:10:21Z")

</div>

> [@smm](#):
>
> at Elasticsearch itself gets killed on the same host (OOM killer).

AFAIK, all 7.x support this. Check does your version has jvm.options. Create a file jvm.options with values:

_Do not modify the root `jvm.options` file. Use files in `jvm.options.d/` instead._  
Copy, set to the same values, save, restart the process.  
-Xms2g  
-Xmx2g

> **[Advanced configuration | Elasticsearch Guide \[7.17\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/advanced-configuration.html)**

---

<div class="post-metadata">

**Author:** ![smm](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@smm](https://discuss.elastic.co/u/smm)\
**Post date:** [May 12, 2022, 11:25am UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/3 "2022-05-12T11:25:59Z")

</div>

> [@smm](#):
>
> OOM killer

I did - and again I get elasticsearch killed since no ram left (logstash / elasticsearch / kibana running on the same machine). Could it be some kind of memory leak of logstash / of a logstash plugin? Mainly using the tcp plugin for logstash and some filter definitions.

Cheers!

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 12, 2022, 11:34am UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/4 "2022-05-12T11:34:23Z")

</div>

LS memory concussion depends on data/queue. How many data records are you processing per minute? How many GBs is your limit?  
It might be a memory leak, depend on version. Not sure.

---

<div class="post-metadata">

**Author:** ![smm](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@smm](https://discuss.elastic.co/u/smm)\
**Post date:** [May 12, 2022, 11:38am UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/5 "2022-05-12T11:38:13Z")

</div>

Can someone from Elastic please tell if versions 7.5.x do have some kind of know memory leaks involved?  
Thank you!

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 12, 2022, 11:40am UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/6 "2022-05-12T11:40:57Z")

</div>

Check release notes:

> **[Release Notes | Logstash Reference \[7.17\] | Elastic](https://www.elastic.co/guide/en/logstash/7.17/releasenotes.html)**

- Fix: eliminates a crash that could occur at pipeline startup when the pipeline references a java-based plugin that had been installed via offline plugin pack [#11340](https://github.com/elastic/logstash/pull/11340)

Also enable temporarily debug info to see any cause.  
For sure, Elastic team can advice more.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 12, 2022, 12:44pm UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/7 "2022-05-12T12:44:55Z")

</div>

What are the specs of the machine? How much memory is set for the heap of Logstash and Elasticsearch? Please share it.

Also how did you track the cause to Logstash since it is Elasticsearch that is getting killed?

If you are constantly getting OOM, maybe the specs of your machine does not fit your use, the JVM uses memory besides the HEAP, Logstash and Elasticsearch needs more memory than is specified in the Heap settings.

---

<div class="post-metadata">

**Author:** ![smm](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@smm](https://discuss.elastic.co/u/smm)\
**Post date:** [May 12, 2022, 12:59pm UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/8 "2022-05-12T12:59:18Z")

</div>

Thanks for asking. These are my specs:  
1 cluster built of 3 all-in-one nodes (meaning: elasrticsearch with master & data roles, kibana and logstash on the same node) and with 2 other nodes (only as data nodes).  
each nodes has:  
30GB RAM  
8 VCPU  
Disk : 40GB  
SSD: 600GB

limits.conf:  
|Elasticsearch|-|nofile|65536|  
|Elasticsearch|-|nproc|4096|  
|logstash|-|nproc|1024|

/etc/logstash/jvm.options:  
-Xms2g  
-Xmx2g

/etc/Elasticsearch/jvm.options:  
-Xms12g  
-Xmx12g

logstash.conf:  
input {  
tcp {  
port =\> 5518  
codec =\> "fluent"  
...

And:  
[14:54] Kraenzlein, Ralph  
java.io.IOException: Too many open files  
in the logstash log

here all the events come in (40-60GB per day)  
cheers

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 12, 2022, 1:20pm UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/9 "2022-05-12T13:20:19Z")

</div>

> [@smm](#):
>
> Too many open files

Check this [Logstash not closing connections correctly · Issue #4225 · elastic/logstash · GitHub](https://github.com/elastic/logstash/issues/4225)

---

<div class="post-metadata">

**Author:** ![smm](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@smm](https://discuss.elastic.co/u/smm)\
**Post date:** [May 14, 2022, 5:11am UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/10 "2022-05-14T05:11:08Z")

</div>

I would like to give a final solution on this. The reason for getting out of memory kills by the kernel was elastalert that is using at peaks nearly double to much memory than Elasticsearch itself.  
Sadly I do not know how to influence this bad behaviour of elastalert.  
cheers

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 14, 2022, 12:26pm UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/11 "2022-05-14T12:26:38Z")

</div>

Simply, out of memory or simple the memory is overtaken by other app. However the most important is you have solved the issue. Well done. 👍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2022, 12:27pm UTC](https://discuss.elastic.co/t/limit-logstash-7-5-memory-usage/304556/12 "2022-06-11T12:27:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
