# Logstash is taking long time to load config and run?

**URL:** <https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736>\
**Category:** Logstash\
**Created:** [June 6, 2018, 6:53am UTC](https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736 "2018-06-06T06:53:12Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![RameshNagargoje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rameshnagargoje/32/30212_2.png) [@RameshNagargoje](https://discuss.elastic.co/u/RameshNagargoje)\
**Post date:** [June 6, 2018, 6:53am UTC](https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736/1 "2018-06-06T06:53:12Z")

</div>

Hi,  
My Logstash is taking 15 minutes to start if I have increased the size of config file .Althougth i have increasedsize of jvm heap not getting why this is happening.

---

<div class="post-metadata">

**Author:** ![nikhil.k](https://avatars.discourse-cdn.com/v4/letter/n/5daacb/32.png) [@nikhil.k](https://discuss.elastic.co/u/nikhil.k)\
**Post date:** [June 6, 2018, 9:36am UTC](https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736/2 "2018-06-06T09:36:12Z")

</div>

Hi @RameshNagargoje,

Use VisualVM tool to troubleshoot the logstash. I hope it may help you.

Regards  
Nikhil Kapoor

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 6, 2018, 12:22pm UTC](https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736/3 "2018-06-06T12:22:21Z")

</div>

Perhaps related to [https://github.com/elastic/logstash/issues/5507](https://github.com/elastic/logstash/issues/5507) or [https://github.com/elastic/logstash/issues/6117](https://github.com/elastic/logstash/issues/6117).

---

<div class="post-metadata">

**Author:** ![RameshNagargoje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rameshnagargoje/32/30212_2.png) [@RameshNagargoje](https://discuss.elastic.co/u/RameshNagargoje)\
**Post date:** [June 8, 2018, 11:28am UTC](https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736/4 "2018-06-08T11:28:38Z")

</div>

Thanks @nikhil.k @magnusbaeck,  
Is there size limit for Logstash config file? Because my config file is 14k lines if i have removed some lines from 14k to 1400 it loads but take some time .

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 8, 2018, 11:56am UTC](https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736/5 "2018-06-08T11:56:52Z")

</div>

I don't think there's a hard limit, but the config file parser might be so inefficient that such large files become unusable.

---

<div class="post-metadata">

**Author:** ![RameshNagargoje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rameshnagargoje/32/30212_2.png) [@RameshNagargoje](https://discuss.elastic.co/u/RameshNagargoje)\
**Post date:** [June 11, 2018, 9:21am UTC](https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736/6 "2018-06-11T09:21:13Z")

</div>

thank you @magnusbaeck ,

I am not getting how to optimize config file ,if we have 1k + regex to match and every regex match add some different tag

Adding Snippet of config

input  
{

}  
filter  
{  
if[logType] == "syslog"  
{  
grok  
{  
match =\> { message =\> "org.bluez.Error"}  
add\_tag =\> ["regexMatched"]  
}  
if "regexMatched" in [tags]  
{  
mutate  
{  
add\_field =\> {"tagName"=\>"Bluetooth\_org.bluez.Error"}  
add\_field =\> {"module" =\> "comms"}  
add\_tag =\> ["SUCCESS"]  
remove\_tag =\>"regexMatched"  
}  
}

```
    grok
    {
        match => { message => "hci0 command .* timeout"}
        add_tag => ["regexMatched"]
    }
    if "regexMatched" in [tags]
    {
        mutate
        {
            add_field => {"tagName"=>"Bluetooth_hci0_command_timeout"}
            add_field => {"module" => "comms"}
            add_tag => ["SUCCESS"]
            remove_tag =>"regexMatched"
        }
    }
     
    grok
    {
        match => { message => "Error resetting SDIO communications"}
        add_tag => ["regexMatched"]
    }
    if "regexMatched" in [tags]
    {
        mutate
        {
            add_field => {"tagName"=>"Error resetting SDIO communications"}
            add_field => {"module" => "comms"}
            add_tag => ["SUCCESS"]
            remove_tag =>"regexMatched"
        }
    }
     
    grok
    {
        match => { message => "\(NvCapture\) Error"}
        add_tag => ["regexMatched"]
    }
    if "regexMatched" in [tags]
    {
        mutate
        {
            add_field => {"tagName"=>"NvCapture"}
            add_field => {"module" => "camera"}
            add_tag => ["SUCCESS"]
            remove_tag =>"regexMatched"
        }
    }
     
    grok
    {
        match => { message => "\(Argus\) Error"}
        add_tag => ["regexMatched"]
    }
    if "regexMatched" in [tags]
    {
        mutate
        {
            add_field => {"tagName"=>"Argus"}
            add_field => {"module" => "camera"}
            add_tag => ["SUCCESS"]
            remove_tag =>"regexMatched"
        }
    }
     }

```

}  
output{  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 11, 2018, 10:11am UTC](https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736/7 "2018-06-11T10:11:46Z")

</div>

> grok  
> {  
> match =\> { message =\> "hci0 command .\* timeout"}  
> add\_tag =\> ["regexMatched"]  
> }  
> if "regexMatched" in [tags]  
> {  
> mutate  
> {  
> add\_field =\> {"tagName"=\>"Bluetooth\_hci0\_command\_timeout"}  
> add\_field =\> {"module" =\> "comms"}  
> add\_tag =\> ["SUCCESS"]  
> remove\_tag =\>"regexMatched"  
> }  
> }

Shorter:

```plaintext
if [message] =~ /hci0 command .* timeout/ {
  mutate {
    add_field => {
      "tagName"=>"Bluetooth_hci0_command_timeout"
      "module" => "comms"
    }
    add_tag => ["SUCCESS"]
  }
}

```

You should also be able to use a translate filter to list multiple regexps.

---

<div class="post-metadata">

**Author:** ![RameshNagargoje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rameshnagargoje/32/30212_2.png) [@RameshNagargoje](https://discuss.elastic.co/u/RameshNagargoje)\
**Post date:** [June 20, 2018, 12:42pm UTC](https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736/8 "2018-06-20T12:42:29Z")

</div>

thank you @magnusbaeck it worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2018, 12:42pm UTC](https://discuss.elastic.co/t/logstash-is-taking-long-time-to-load-config-and-run/134736/9 "2018-07-18T12:42:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
