# Logstah performance issues

**URL:** <https://discuss.elastic.co/t/logstah-performance-issues/99128>\
**Category:** Logstash\
**Created:** [September 1, 2017, 12:52pm UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128 "2017-09-01T12:52:40Z")\
**Posts on this page:** 10\
**Page:** 2

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 11, 2017, 1:35pm UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128/21 "2017-09-11T13:35:02Z")

</div>

It would be better to use:

```auto
dissect {
  mapping => {
    "message" => "...,%{?onething}" 
}

```

Effectively, field `onething` will never be added, so it would not have to be removed. Of course, if the `message` field is no longer needed, it would be appropriate to have `remove_field => ["message"]` still, as it will only remove if the conversion is successful and has no errors.

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [September 11, 2017, 2:11pm UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128/22 "2017-09-11T14:11:09Z")

</div>

Good, ty.

I test dissect filter and i have a probleme.

(Sometimes my fields are empty)

Few fields are shifted and take the wrong value...

even so, in Excel, my conf is good on log lines. I don't know where the problem comes from.

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [September 11, 2017, 2:27pm UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128/23 "2017-09-11T14:27:51Z")

</div>

Caused by: java.lang.NumberFormatException: For input string: "FU\_USAGE\_OP"  
at java.lang.NumberFormatException.forInputString(NumberFormatException.java:65) ~[?:1.8.0\_131]

Here one of error. i have full error of this type.

Ok @theuntergeek , If my fields are empty, the values are assigned to the wrong field. How to resolve it ?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 11, 2017, 2:59pm UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128/24 "2017-09-11T14:59:20Z")

</div>

You may be compelled to use the `csv` filter if you have empty fields. I believe it handles those properly, where the `dissect` filter does not. However, that may or may not be true until you test it and find out.

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [September 11, 2017, 3:05pm UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128/25 "2017-09-11T15:05:38Z")

</div>

> [@theuntergeek](#):
>
> You may be compelled to use the csv filter if you have empty fields. I believe it handles those properly, where the dissect filter does not. However, that may or may not be true until you test it and find out

I have empty filed only sometimes not always 😕

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 11, 2017, 3:18pm UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128/26 "2017-09-11T15:18:37Z")

</div>

Indeed, but the cost of trying to figure out which ones need to be shifted is too high. You should use the `csv` filter to see if it catches those properly. Otherwise, you're going to have a lot of work to try to figure out how to either omit or reprocess lines that have missing fields.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [September 11, 2017, 4:34pm UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128/27 "2017-09-11T16:34:44Z")

</div>

FYI, I have a change to Dissect that handles empty fields better but it has not been released - the Pull Request is in the review stage.

---

<div class="post-metadata">

**Author:** ![suyograo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyograo/32/44898_2.png) [@suyograo](https://discuss.elastic.co/u/suyograo)\
**Post date:** [September 11, 2017, 4:45pm UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128/28 "2017-09-11T16:45:51Z")

</div>

I changed the topic to be more constructive.

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [September 12, 2017, 9:05am UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128/29 "2017-09-12T09:05:48Z")

</div>

> [@guyboertje](#):
>
> FYI, I have a change to Dissect that handles empty fields better but it has not been released - the Pull Request is in the review stage.

Good, i think swith to dissect afeter this changement.

Thank you for help all

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2017, 9:05am UTC](https://discuss.elastic.co/t/logstah-performance-issues/99128/30 "2017-10-10T09:05:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/logstah-performance-issues/99128.md?page=1)
