# Logstash Exec Input Plugin throws OutofMemory Error

**URL:** <https://discuss.elastic.co/t/logstash-exec-input-plugin-throws-outofmemory-error/146172>\
**Category:** Logstash\
**Created:** [August 27, 2018, 12:04pm UTC](https://discuss.elastic.co/t/logstash-exec-input-plugin-throws-outofmemory-error/146172 "2018-08-27T12:04:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dheeraj\_Gupta](https://avatars.discourse-cdn.com/v4/letter/d/49beb7/32.png) [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Post date:** [August 27, 2018, 12:04pm UTC](https://discuss.elastic.co/t/logstash-exec-input-plugin-throws-outofmemory-error/146172/1 "2018-08-27T12:04:15Z")

</div>

Hi,

We are running a program to read some events off our API and send them to Elasticsearch. Since http poller plugin does not support dynamic parameters (in our case timestamp when last poll was done), we use a custom shell script which keeps track of last event pulled and calls API for all events since that event. The shell script is run using `exec` input plugin. Our logstash version is 6.3.2.

The exec plugin worked correctly for some time but lately we see errors like

> [ERROR][logstash.inputs.exec] Error while running command {:command=\>"/usr/local/scripts/snort\_alerts 2\> /dev/null", :e=\>#\<Errno::ENOMEM: Cannot allocate memory - /usr/local/scripts/snort\_alerts 2\> /dev/null\>, :backtrace=\>["org/jruby/RubyIO.java:3835:in `popen'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-exec-3.3.1/lib/logstash/inputs/exec.rb:97:in `run\_command'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-exec-3.3.1/lib/logstash/inputs/exec.rb:71:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-exec-3.3.1/lib/logstash/inputs/exec.rb:52:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:512:in `inputworker'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:505:in `block in start\_input'"]}

It appears like `exec` cannot spawn the child process. Rest of logstash/system works correctly and all other pipelines continue processing.

The system has 16GB RAM and Logstash has `-Xmx` and `-Xms` set to `8g`. The snapshot of `free -m` when we see the errors is

```
$ free -m
              total used free shared buff/cache available
Mem: 15508 8700 5389 167 1418 6266
Swap: 1906 255 1651

```

The plugin configuration is

```
input {
	exec {
		command => "/usr/local/scripts/snort_alerts 2> /dev/null"
		interval => 60
		codec => "json"
		type => "snort_alert"
	}
}

```

Restarting logstash temporarily corrects the problem but it reappears after some time.

The [code for plugin](https://github.com/logstash-plugins/logstash-input-exec/blob/db5f1da773717f7ed36a7c744e1998108ecc432b/lib/logstash/inputs/exec.rb#L97) uses `IO.popen` to spawn the subprocess but [this answer on Stackoverflow](https://stackoverflow.com/a/20474736/533524) says using `IO.popen` calls the `fork` system call which duplicates entire memory space of parent process (in this case logstash). Could this be the problem?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 24, 2018, 12:04pm UTC](https://discuss.elastic.co/t/logstash-exec-input-plugin-throws-outofmemory-error/146172/2 "2018-09-24T12:04:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
