# Logstash 2.2 OutOfMemoryError

**URL:** <https://discuss.elastic.co/t/logstash-2-2-outofmemoryerror/43710>\
**Category:** Logstash\
**Created:** [March 7, 2016, 9:53pm UTC](https://discuss.elastic.co/t/logstash-2-2-outofmemoryerror/43710 "2016-03-07T21:53:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jim\_Jepson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jim_jepson/32/8777_2.png) [@Jim\_Jepson](https://discuss.elastic.co/u/Jim_Jepson)\
**Post date:** [March 7, 2016, 9:53pm UTC](https://discuss.elastic.co/t/logstash-2-2-outofmemoryerror/43710/1 "2016-03-07T21:53:32Z")

</div>

We are trying to use Winlogbeats to archive off our Windows logs. To start this, we setup a Linux server running the latest ELK. On one of our three Windows 2012 R2 DC's we setup winlogbeats to ship the logs to the Ubuntu ELK server. It runs for awhile but eventually Logstash crashes. I see that it is out of memory. How much should I set the cap to? This is just one of three DC's and we were hoping to ship other logs to it also? I think we were getting about 10 records/sec sent to it. I find it hard to believe that we overloaded it?

Here is what we are getting in the in logstash.err.1:

```auto
Mar 04, 2016 2:45:00 AM org.apache.http.impl.execchain.RetryExec execute
INFO: I/O exception (java.net.SocketException) caught when processing request to {}->http://localhost:9200: Socket closed
Mar 04, 2016 2:45:00 AM org.apache.http.impl.execchain.RetryExec execute
INFO: Retrying request to {}->http://localhost:9200
Error: Your application used more memory than the safety cap of 1G.
Specify -J-Xmx####m to increase it (#### = cap size in MB).
Specify -w for full OutOfMemoryError stack trace

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 7, 2016, 9:57pm UTC](https://discuss.elastic.co/t/logstash-2-2-outofmemoryerror/43710/2 "2016-03-07T21:57:15Z")

</div>

Are you using LSF here? Cause you've posted it in that category.

---

<div class="post-metadata">

**Author:** ![Jim\_Jepson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jim_jepson/32/8777_2.png) [@Jim\_Jepson](https://discuss.elastic.co/u/Jim_Jepson)\
**Post date:** [March 7, 2016, 10:00pm UTC](https://discuss.elastic.co/t/logstash-2-2-outofmemoryerror/43710/3 "2016-03-07T22:00:17Z")

</div>

Sorry, changed it.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 8, 2016, 5:35pm UTC](https://discuss.elastic.co/t/logstash-2-2-outofmemoryerror/43710/4 "2016-03-08T17:35:47Z")

</div>

That's looks like a Logstash OOM issue not a Winlogbeat issue. We can help you better if you list the specific versions of Winlogbeat, Logstash, Java, and your operating systems. Also provide the configuration files that are being used.

---

<div class="post-metadata">

**Author:** ![Jim\_Jepson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jim_jepson/32/8777_2.png) [@Jim\_Jepson](https://discuss.elastic.co/u/Jim_Jepson)\
**Post date:** [March 8, 2016, 9:25pm UTC](https://discuss.elastic.co/t/logstash-2-2-outofmemoryerror/43710/5 "2016-03-08T21:25:17Z")

</div>

Below are my configs. Any help or suggestions are greatly appreciated!

**Logstash server:**  
Ubuntu 14.04  
Java - Oracle Java 8  
Logstash 2.2  
ElasticSearch 2.2.0

**Logstash Configs:**

02-beats-input.conf

```
    input {
      beats {
        port => 5044
        ssl => true
        ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
        ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
      }
    }

```

30-elasticsearch-output.conf

```
output {
  elasticsearch {
    hosts => ["localhost:9200"]
    sniffing => true
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

10-syslog-filter.conf

```
filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

```

**Beats Client**  
Windows Server 2012 R2  
Winlogbeat.1.1.1

winlogbeat.yml

```auto
winlogbeat:
  registry_file: C:/ProgramData/winlogbeat/.winlogbeat.yml

  event_logs:
    - name: Application
      ignore_older: 1h 
    - name: Security
    - name: System
      ignore_older: 1h
  metrics:
    bindaddress: 'localhost:8123'
output:
  logstash:
    hosts: ["logserver.mydomain.com:5044"]
    index: winlogbeat
    tls:
      certificate_authorities: ["/apps/beats/certs/logstash-forwarder.crt"]

shipper:
logging:
  to_files: true
  files:
    path: C:/ProgramData/winlogbeat/Logs
    rotateeverybytes: 10485760 # = 10MB
  level: info

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:07am UTC](https://discuss.elastic.co/t/logstash-2-2-outofmemoryerror/43710/6 "2017-07-06T05:07:54Z")

</div>


