# Logstash heap size

**URL:** <https://discuss.elastic.co/t/logstash-heap-size/622>\
**Category:** Logstash\
**Created:** [May 13, 2015, 1:29pm UTC](https://discuss.elastic.co/t/logstash-heap-size/622 "2015-05-13T13:29:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![it2](https://avatars.discourse-cdn.com/v4/letter/i/f14d63/32.png) [@it2](https://discuss.elastic.co/u/it2)\
**Post date:** [May 13, 2015, 1:29pm UTC](https://discuss.elastic.co/t/logstash-heap-size/622/1 "2015-05-13T13:29:17Z")

</div>

Hello friends!  
Just say, I'm not an expert in Logstash or elasticsearch.  
I have logstash 1.4.2 cluster, one master and two nodes for data.  
I have a lot of logs sending to my cluster every day. And once, logstash stopped to answer for any of my commands, and without thinking twice I reboot the whole system. Things began to happen again and again.  
Then I found out a parametr LS\_HEAP\_SIZE which I increased from 600m to 8g 😄  
But it didnot help as I expected, and the cluster was felt in 5 days after 8 gb was eatten. It looks like OOM killer.  
How may I perfom my system?  
ES\_HEAP\_SIZE is 4g for master, and 10g for each of nodes.  
My input.conf:

```
    input {

#################################### Cisco

udp {
    port => 60606
    type => syslog
}

#################################### sysLog

tcp {
    port => 10514
    type => syslog
}

#################################### vmWare

tcp {
    port => 1514
    type => syslog
}

################################### GELF

gelf {
    codec => "plain"
    host => "0.0.0.0"
    port => 12201
    type => "gelf"
}

################################ ERLANG
udp {
    codec => "json"
    host => "0.0.0.0"
    port => 12211
    type => "erlang"
}

```

Meanwhile, i found this article: [https://github.com/logstash-plugins/logstash-input-lumberjack/issues/10](https://github.com/logstash-plugins/logstash-input-lumberjack/issues/10) and think that it's my resolve, but I have only UDP and TCP and GELF inputs ☹  
Please give me some advice, thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 13, 2015, 6:42pm UTC](https://discuss.elastic.co/t/logstash-heap-size/622/2 "2015-05-13T18:42:23Z")

</div>

Logstash 1.4.2 has a memory leak in the TCP input.

> <https://github.com/elastic/logstash/issues/1509>
>
> Suspected TCP Input leak and/or overload condition.
> This error message is returned gradually, increasing over time to a constant stream of this...

I think it's very disturbing that a 1.4.3 release wasn't released with a fix for this bug. Switch to the most recent Logstash 1.5.0 candidate or build your own 1.4.2 with the small patch that's required.

---

<div class="post-metadata">

**Author:** ![it2](https://avatars.discourse-cdn.com/v4/letter/i/f14d63/32.png) [@it2](https://discuss.elastic.co/u/it2)\
**Post date:** [May 14, 2015, 7:06am UTC](https://discuss.elastic.co/t/logstash-heap-size/622/3 "2015-05-14T07:06:42Z")

</div>

Thank you for answer!  
I will study that issue.

---

<div class="post-metadata">

**Author:** ![it2](https://avatars.discourse-cdn.com/v4/letter/i/f14d63/32.png) [@it2](https://discuss.elastic.co/u/it2)\
**Post date:** [May 22, 2015, 12:41pm UTC](https://discuss.elastic.co/t/logstash-heap-size/622/4 "2015-05-22T12:41:53Z")

</div>

Today I update my logstash to 1.5.0 and ES to 1.5.2  
But LS\_HEAP\_SIZE still increasing. It is going slower than was at 1.4.2 version but it's increasing.  
What i can do? Need I to install ES 1.5.2 to my data nodes?

---

<div class="post-metadata">

**Author:** ![it2](https://avatars.discourse-cdn.com/v4/letter/i/f14d63/32.png) [@it2](https://discuss.elastic.co/u/it2)\
**Post date:** [May 22, 2015, 12:55pm UTC](https://discuss.elastic.co/t/logstash-heap-size/622/5 "2015-05-22T12:55:16Z")

</div>

Maybe i wrong, because it's java, and the more I give, the more it eats...

---

<div class="post-metadata">

**Author:** ![it2](https://avatars.discourse-cdn.com/v4/letter/i/f14d63/32.png) [@it2](https://discuss.elastic.co/u/it2)\
**Post date:** [May 23, 2015, 10:35am UTC](https://discuss.elastic.co/t/logstash-heap-size/622/6 "2015-05-23T10:35:26Z")

</div>

Nope, LS HEAP SIZE was increased to 8 gb and my cluster died...  
Any advices guys?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/logstash-heap-size/622/7 "2017-07-06T05:39:26Z")

</div>


