# Logstash CPU usage issue after some time running

**URL:** <https://discuss.elastic.co/t/logstash-cpu-usage-issue-after-some-time-running/124823>\
**Category:** Logstash\
**Created:** [March 20, 2018, 4:42pm UTC](https://discuss.elastic.co/t/logstash-cpu-usage-issue-after-some-time-running/124823 "2018-03-20T16:42:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lael](https://avatars.discourse-cdn.com/v4/letter/l/5f8ce5/32.png) [@lael](https://discuss.elastic.co/u/lael)\
**Post date:** [March 20, 2018, 4:42pm UTC](https://discuss.elastic.co/t/logstash-cpu-usage-issue-after-some-time-running/124823/1 "2018-03-20T16:42:31Z")

</div>

After some time of operation, our logstash instances (same configuration) are experiencing CPU and load average issues as shown below.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e38c14461767fd32ddfad0d934298468c86092e.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a4a59e773aded806bcec3849fae1947cb4468a9c.png)

When the issue occurs we have to restart the impacted logstash instance for it to behave normally again (on the above graph, it has been restarted at the vertical bar) for about 24H until the next issue occurs.  
If we delay the restart between two instances, the issue is delayed by about the same time so it does not look like to be related to the ingested events.

We are running logstash 5.6.8 from the rpm repository.  
With the following additional plugins:

- x-pack
- logstash-filter-translate

And the following configuration:

- jvm.options

> -Xms5g  
> -Xmx6g  
> -XX:+UseParNewGC  
> -XX:+UseConcMarkSweepGC  
> -XX:CMSInitiatingOccupancyFraction=75  
> -XX:+UseCMSInitiatingOccupancyOnly  
> -XX:+DisableExplicitGC  
> -Djava.awt.headless=true  
> -Dfile.encoding=UTF-8  
> -XX:+HeapDumpOnOutOfMemoryError

- logstash.yml

> node.name: logstash1  
> path.data: /var/lib/logstash  
> pipeline.workers: 8  
> pipeline.batch.size: 250  
> pipeline.batch.delay: 5  
> path.config: /etc/logstash/conf.d  
> log.level: info  
> path.logs: /var/log/logstash  
> xpack.monitoring.enabled: true  
> xpack.monitoring.collection.interval: 10s  
> xpack.monitoring.elasticsearch.url: ["[http://elastic1:9200](http://elastic1:9200)","[http://elastic2:9200](http://elastic2:9200)"]  
> xpack.monitoring.elasticsearch.username: xpack\_monitoring  
> xpack.monitoring.elasticsearch.password: \*\*\*\*\*\*\*\*\*

And no error messages in logstash-plain.log.

We were doing lots of updates in the filters and had to restart the instance quite often so we did not notice the issue until after some time.  
In the meantime we have also updated to 5.6.8 and installed xpack monitoring.  
I don't know exactly which of the previous action caused the issue.  
It worked without issue for about a year before that.

Any idea ?

---

<div class="post-metadata">

**Author:** ![lael](https://avatars.discourse-cdn.com/v4/letter/l/5f8ce5/32.png) [@lael](https://discuss.elastic.co/u/lael)\
**Post date:** [March 30, 2018, 9:21am UTC](https://discuss.elastic.co/t/logstash-cpu-usage-issue-after-some-time-running/124823/2 "2018-03-30T09:21:36Z")

</div>

I tried updating my logstash instances to version 6.2.3 from version 5.6.8 with the exact same configuration and plugins.  
Everything is now working fine: no more high CPU/load average, etc...

And no side effects in forwarding logs from logstash 6.2.3 to elasticsearch 5.6.8.

There is definitely an issue with logstash version 5.6.8.

Below the graphs now that the logstash instance is working as intended

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/2/b23fd7146eade72189f409b1ef2ae297361d5dfc.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55a124c44f2569e7ef593cb106ef7059b8abe2a7.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2018, 9:21am UTC](https://discuss.elastic.co/t/logstash-cpu-usage-issue-after-some-time-running/124823/3 "2018-04-27T09:21:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
