# Logstash HeapDumpOnOutOfMemoryError

**URL:** <https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161>\
**Category:** Logstash\
**Created:** [February 23, 2017, 6:31am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161 "2017-02-23T06:31:21Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![higee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/higee/32/22343_2.png) [@higee](https://discuss.elastic.co/u/higee)\
**Post date:** [February 23, 2017, 6:31am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161/1 "2017-02-23T06:31:22Z")

</div>

Hi.

I'm using Logstash to extract data from Database and send data to Elasticsearch.  
Everything works fine; data is well processed and sent to Elasticsearch without loss.

The problem, however, is burden on the server.  
I'm running four logstash.conf files on AWS ec2 instance.  
I checked process viewer and found out that logstash files are eating too much memory.  
Please refer to following screenshot.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/b16fe9c4681f1e9971d8e5b0e07e6331b9071a4d.png)

Any comment or feedback would be immensely helpful.

Best

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 27, 2017, 6:38am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161/2 "2017-02-27T06:38:14Z")

</div>

What does your configuration look like?

---

<div class="post-metadata">

**Author:** ![higee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/higee/32/22343_2.png) [@higee](https://discuss.elastic.co/u/higee)\
**Post date:** [February 27, 2017, 7:22am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161/3 "2017-02-27T07:22:32Z")

</div>

Thanks for the comment @magnusbaeck.

What do you mean by configuration?

`logstash`  
If it's regarding **logstash.yml** , I haven't change any.  
I've installed logstash-5.2.0, so it should be the default configuration.

`elasticsearch`  
I'm using elastic cloud(5.1.1), and same as above, I haven't changed any.

`server (aws ec2)`

- memory : 4G
- cpu cores : 2

* * *

I'm attaching the result of `jvmtop` command for your reference.

Best

Gee

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/e00a07f9fa0567d57908448981989d50313aa6f8.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 27, 2017, 8:25am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161/4 "2017-02-27T08:25:30Z")

</div>

> What do you mean by configuration?

Your Logstash configuration files (typically /etc/logstash/conf.d/\*).

---

<div class="post-metadata">

**Author:** ![higee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/higee/32/22343_2.png) [@higee](https://discuss.elastic.co/u/higee)\
**Post date:** [February 28, 2017, 2:06am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161/5 "2017-02-28T02:06:21Z")

</div>

As I mentioned above, I haven't changed any since the installation.

- logstash.yml [click](https://goo.gl/DkuQuP)
- jvm.options [click](https://goo.gl/LnGWdj)
- log4j2.properties [click](https://goo.gl/n2crWE)
- startup.options [click](https://goo.gl/RxdBpv)

I've attached all my configuration files via google drive.

Best

Gee

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 28, 2017, 6:54am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161/6 "2017-02-28T06:54:17Z")

</div>

I'm asking for the (four?) files that you probably have in /etc/logstash/conf.d/\*.

---

<div class="post-metadata">

**Author:** ![higee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/higee/32/22343_2.png) [@higee](https://discuss.elastic.co/u/higee)\
**Post date:** [March 2, 2017, 2:52am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161/7 "2017-03-02T02:52:13Z")

</div>

```auto
input {
    jdbc {
        jdbc_validate_connection => true
        jdbc_connection_string => "jdbc:oracle:thin:@HOST:PORT/SERVICE_NAME"
        jdbc_user => "USER_NAME"
        jdbc_password => "PASSWORD"
        jdbc_driver_library => "/Users/ojdbc7.jar"
        jdbc_driver_class => "Java::oracle.jdbc.driver.OracleDriver"
        statement => "SELECT * FROM TABLE" # more complex
    }
}

filter { # I'm using mutate, date, if filter
}

output {
    elasticsearch {
        index => "INDEX"
        documents_type => "TYPE"
        hosts => ["URL.ap-northeast-1.aws.found.io:9200/"] #elasticcloud
        user => "ID"
        password => "PASSWORD"
    }
}

```

Four configuration files share basic outline shown above.  
Please let me know if you need more information to tackle this problem.

Best

Gee

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2017, 6:57am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161/8 "2017-03-02T06:57:30Z")

</div>

Hmm. Looking closer at the screenshot I'm not sure it's so alarming. It's using a lot of virtual address space, but not much is resident. Are we looking at different threads of the same JVM process or are you actually running dozens of Logstash processes?

---

<div class="post-metadata">

**Author:** ![higee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/higee/32/22343_2.png) [@higee](https://discuss.elastic.co/u/higee)\
**Post date:** [March 2, 2017, 8:37am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161/9 "2017-03-02T08:37:14Z")

</div>

> Are we looking at different threads of the same JVM process or are you actually running dozens of Logstash processes?

running 4 logstash processes.

As I've mentioned, I got 4 logstash conf files that looks like the one I uploaded.  
Then on the server, I run following command to run them in the background.

```
nohup bin/logstash -f logstash1.conf &
nohup bin/logstash -f logstash2.conf &
nohup bin/logstash -f logstash3.conf &
nohup bin/logstash -f logstash4.conf &

```

But I don't think the number of logstash file matters a lot.  
I checked heap memory while running only one logstash but got the same error, 'HeapDumpOnOutOfMemory'.

I'll be looking forward to hearing from you.

Best

Gee

------UPDATED------

If you're talking about JVM, yes each logstash is producong approximately 10 threads, thus provoking 'HeapDumpOnOutOfMemoryError'.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2017, 8:37am UTC](https://discuss.elastic.co/t/logstash-heapdumponoutofmemoryerror/76161/10 "2017-03-30T08:37:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
