# Logstash 2.2.1 and 492s all over the place

**URL:** <https://discuss.elastic.co/t/logstash-2-2-1-and-492s-all-over-the-place/41841>\
**Category:** Logstash\
**Created:** [February 16, 2016, 5:51am UTC](https://discuss.elastic.co/t/logstash-2-2-1-and-492s-all-over-the-place/41841 "2016-02-16T05:51:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcin\_Kubica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcin_kubica/32/5614_2.png) [@Marcin\_Kubica](https://discuss.elastic.co/u/Marcin_Kubica)\
**Post date:** [February 16, 2016, 5:51am UTC](https://discuss.elastic.co/t/logstash-2-2-1-and-492s-all-over-the-place/41841/1 "2016-02-16T05:51:34Z")

</div>

Hi

I have a 6 node es cluster and trying to run two instances of logstash against it.  
Both piping into stdin, hosts =\> set with all nodes, and with default 4 workers and they return me 492s instantly.

If I set workers to 1 they're good however getting poor indexing speed. And adding another two instances with single workers makes ES screaming again 🙂

Any tips would be appreciated. I don't think previous pipeline was doing this bad?

Many thanks!  
Marcin

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 16, 2016, 12:17pm UTC](https://discuss.elastic.co/t/logstash-2-2-1-and-492s-all-over-the-place/41841/2 "2016-02-16T12:17:45Z")

</div>

What is the specification and configuration of your cluster? What is your heap size? Is there anything in the Elasticsearch logs? What type of data are you indexing?

---

<div class="post-metadata">

**Author:** ![Marcin\_Kubica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcin_kubica/32/5614_2.png) [@Marcin\_Kubica](https://discuss.elastic.co/u/Marcin_Kubica)\
**Post date:** [February 23, 2016, 11:41pm UTC](https://discuss.elastic.co/t/logstash-2-2-1-and-492s-all-over-the-place/41841/3 "2016-02-23T23:41:11Z")

</div>

Hi @Christian_Dahlqvist

Thanks for quick response.

I'm using default config for the time being. Got 7 nodes, 8GB heap each for the time being

I've found by mistake my index templates were trying to allocate 333 shards per index. I've got this silly lag on my putty client and sometimes this mistake happens.

After correcting I could easily spawn 50 workers and had no issues.

I'm judging queue capacity overflow. I've pasted log excerpts to [http://pastebin.com/raw/VBbYcDaY](http://pastebin.com/raw/VBbYcDaY) as they did not fit here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:10am UTC](https://discuss.elastic.co/t/logstash-2-2-1-and-492s-all-over-the-place/41841/4 "2017-07-06T05:10:00Z")

</div>


