# Logstash 2.1 is filling my Disk volumes

**URL:** <https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924>\
**Category:** Logstash\
**Created:** [March 20, 2016, 5:57am UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924 "2016-03-20T05:57:08Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![soodlikesjava](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@soodlikesjava](https://discuss.elastic.co/u/soodlikesjava)\
**Post date:** [March 20, 2016, 5:57am UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/1 "2016-03-20T05:57:08Z")

</div>

Hi Team , I am facing an issue that when my logstash process is running for 4-5 days , my disk volume on the machine where logstash is installed is getting exhausted and i have to restart the logstash process to free the volume . Can anyone please let me know how logstash exhausts the volumes on the machine.

Volume when logstash was running 🙂

root 61G 61G 32K 100% /

Volume when logstash is restarted :  
root 61G 25G 36G 41% /

---

<div class="post-metadata">

**Author:** ![ebuildy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebuildy/32/6070_2.png) [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Post date:** [March 20, 2016, 3:56pm UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/2 "2016-03-20T15:56:51Z")

</div>

Hello, please add your logstash configuration.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 20, 2016, 4:10pm UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/3 "2016-03-20T16:10:15Z")

</div>

Well, what's taking up all that space? `du` should give some clues.

---

<div class="post-metadata">

**Author:** ![soodlikesjava](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@soodlikesjava](https://discuss.elastic.co/u/soodlikesjava)\
**Post date:** [March 20, 2016, 5:12pm UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/4 "2016-03-20T17:12:23Z")

</div>

PFB my configurations :  
input {

redis {  
host =\> '[xx.xx.xxx.xxx](http://xx.xx.xxx.xxx)'  
port =\> 1234  
password =\> 'passwd'  
data\_type =\> 'list'  
key =\> 'key'  
}  
}

filter {

if("abcdsf" in [tags])  
{

grok {  
match =\> { "message" =\> "^=%{WORD:report\_type} REPORT=+ (?%{MONTHDAY}-%{MONTH}-%{YEAR}::%{HOUR}:%{MINUTE}:%{SECOND}) ===.\*$" }  
}

multiline {  
pattern =\> "(^=)"  
negate =\> true  
what =\> "previous"  
}  
}  
else {  
multiline {  
pattern =\> "^%{TIMESTAMP\_ISO8601}%{SPACE}%{NUMBER}?%{SPACE}?TRACE"  
what =\> "previous"  
}  
grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:logdate}%{SPACE}%{NUMBER:pid}?%{SPACE}?(?AUDIT|CRITICAL|DEBUG|INFO|TRACE|WARNING|ERROR) [?\b%{NOTSPACE:mod}\b]?%{SPACE}?%{GREEDYDATA:logmessage}" }  
}

}  
}

output { stdout { codec =\> rubydebug } }

output {  
elasticsearch {  
hosts =\> ["elasticsearchEndpoint:443"]  
ssl =\> true  
keystore =\> "/etc/pki/Truststore.jks"  
keystore\_password =\> "passwd"  
user =\> "passwd"  
password =\> "passwd"  
index =\> "logstash--%{+YYYY.MM.dd}"  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 20, 2016, 6:52pm UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/5 "2016-03-20T18:52:09Z")

</div>

> output { stdout { codec =\> rubydebug } }

You should remove the two stdout outputs. These cause all events passing through Logstash to be logged twice to Logstash's log file.

---

<div class="post-metadata">

**Author:** ![soodlikesjava](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@soodlikesjava](https://discuss.elastic.co/u/soodlikesjava)\
**Post date:** [March 20, 2016, 7:04pm UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/6 "2016-03-20T19:04:43Z")

</div>

Thanks for verifying the configs but how does the volume usage is reducing just by restarting logstash.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 20, 2016, 7:34pm UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/7 "2016-03-20T19:34:09Z")

</div>

Perhaps because the files that occupied the disk space were deleted while Logstash was running and kept them open, and once Logstash shuts down the disk space was reclaimed.

---

<div class="post-metadata">

**Author:** ![soodlikesjava](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@soodlikesjava](https://discuss.elastic.co/u/soodlikesjava)\
**Post date:** [March 20, 2016, 8:44pm UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/8 "2016-03-20T20:44:52Z")

</div>

As logstash keeps events in persistent queue .Is this contributing to the volume usage .Apart from this which files are kept opened by logstash?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 20, 2016, 8:50pm UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/9 "2016-03-20T20:50:45Z")

</div>

> As logstash keeps events in persistent queue

What persistent queue are you talking about? Logstash has no built-in queue.

> Is this contributing to the volume usage .Apart from this which files are kept opened by logstash?

Let's not spend time speculating. Find out what files are using up the space.

---

<div class="post-metadata">

**Author:** ![soodlikesjava](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@soodlikesjava](https://discuss.elastic.co/u/soodlikesjava)\
**Post date:** [March 20, 2016, 9:47pm UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/10 "2016-03-20T21:47:59Z")

</div>

I attended the elasticOn 2016 and this was the session which explained about persistent queues :  
[https://www.elastic.co/elasticon/conf/2016/sf/dive-deep-with-logstash-from-pipelines-to-persistent-queues](https://www.elastic.co/elasticon/conf/2016/sf/dive-deep-with-logstash-from-pipelines-to-persistent-queues)

So, how can I find out which all files are contributing to disk usage in logstash ?

---

<div class="post-metadata">

**Author:** ![jupp](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jupp](https://discuss.elastic.co/u/jupp)\
**Post date:** [March 20, 2016, 11:51pm UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/11 "2016-03-20T23:51:16Z")

</div>

ls -l /proc/{PID}/fd should tell you what files are open by process.

or

lsof -p {PID}

or

pfiles {PID}

But i think its the logstash log-output.

How do you start logstash? With --debug ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 21, 2016, 7:15am UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/12 "2016-03-21T07:15:20Z")

</div>

> I attended the elasticOn 2016 and this was the session which explained about persistent queues :

I'm pretty sure the Logstash 2.2 pipeline change didn't actually include the persistent queue feature. Secondly, you're running Logstash 2.1 so none of that applies anyway.

> So, how can I find out which all files are contributing to disk usage in logstash ?

As I said `du` would be a good start. @jupp gave a few other useful suggestions.

---

<div class="post-metadata">

**Author:** ![soodlikesjava](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@soodlikesjava](https://discuss.elastic.co/u/soodlikesjava)\
**Post date:** [March 21, 2016, 8:02am UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/13 "2016-03-21T08:02:25Z")

</div>

I am running Logstash process in linux box where i configured DEBUG=1 in logstash.service file .

---

<div class="post-metadata">

**Author:** ![soodlikesjava](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@soodlikesjava](https://discuss.elastic.co/u/soodlikesjava)\
**Post date:** [March 21, 2016, 8:03am UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/14 "2016-03-21T08:03:41Z")

</div>

Thanks magnus for confirming , i will test by disabling the debug and see if still the volumes are getting consumed . I configured DEBUG=1 in logstash.service file .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924/15 "2017-07-06T05:06:08Z")

</div>


