# Logstash is very slow in sending the data to elasticsearch

**URL:** https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130
**Category:** Logstash
**Created:** [January 19, 2017, 8:15am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130 "2017-01-19T08:15:41Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![anisen](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@anisen](https://discuss.elastic.co/u/anisen)
#### Post date: [January 19, 2017, 8:15am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/1 "2017-01-19T08:15:41Z")

</div>

Hi,

I am parsing an IIS log-file which is in below format:

2014-07-12:00:08:54 100.200.50.0 GET /mypath/mypage.asmx - 80 - 100.100.50.0 Mozilla/4.1+(compatible;+MSIE+4.01;+Windows+NT;+MS+Search+8.0+Robot) - 403 0 0 39

And, my logstash config file looks like this:

input {  
file {  
path =\> "D:/myLogFile.log"  
type =\> "iis-log"  
start\_position =\> "beginning"  
}  
}

filter {

grok {  
match =\> {  
"message" =\> '%{DATA:timestamp} %{IPORHOST:clientip} %{NOTSPACE:method} %{NOTSPACE:uri} %{NOTSPACE:csuriquery} %{NOTSPACE:port} %{NOTSPACE:username} %{NOTSPACE:serverip} %{NOTSPACE:agent} %{NOTSPACE:referrer} %{NOTSPACE:status} %{NOTSPACE:sub\_status} %{NOTSPACE:win\_status} %{NOTSPACE:responsetime}'  
}  
}

date {  
match =\> ["timestamp", "YYYY-mm-dd:HH:mm:ss"]  
locale =\> en  
}

}

output {  
elasticsearch {  
action =\> "index"  
hosts =\> "localhost"  
index =\> "myindex"  
}  
}

I am processing around 10 lakh data, for which it is taking around 2 hours, which is much much slower than what I expected.

Kindly suggest how can I increase the performance/ tune the above config file/filter.

Thanks in advance.

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [January 19, 2017, 8:27am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/2 "2017-01-19T08:27:44Z")

</div>

Depending on which version of Logstash you are using, recommended tuning will differ as the pipeline has gone through changes. I would however recommend increasing the number of [workers](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-workers) for the elastic search output a bit as a first step. Start setting this to a reasonably low number and increase this slowly until it no longer improves throughput. A good starting point may be the number of worker threads you have or the number of cores available one the Logstash host.

---

<div class="post-metadata">

### Author: ![Nitz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nitz/32/14599_2.png) [@Nitz](https://discuss.elastic.co/u/Nitz)
#### Post date: [January 19, 2017, 8:38am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/3 "2017-01-19T08:38:15Z")

</div>

+1

We experienced it too. Increasing number of workers didn't helped much.

Would like to get further assistance on this one.

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [January 19, 2017, 8:43am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/4 "2017-01-19T08:43:14Z")

</div>

Which version of Logstash are you using?

---

<div class="post-metadata">

### Author: ![anisen](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@anisen](https://discuss.elastic.co/u/anisen)
#### Post date: [January 19, 2017, 8:55am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/5 "2017-01-19T08:55:43Z")

</div>

Logstash and Elasticsearch both are of 5.1.1 version.

Moreover, it seems workers are depricated in logstash 5.1.1.  
Any alternate to this?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [January 19, 2017, 9:06am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/6 "2017-01-19T09:06:37Z")

</div>

The [documentation](https://www.elastic.co/guide/en/logstash/current/performance-troubleshooting.html) provides some good guidance on troubleshooting performance. Increasing the number of workers in the Elasticsearch output is one of the things discussed there.

What is the hardware specification of you Logstash host and Elasticsearch cluster?

---

<div class="post-metadata">

### Author: ![anisen](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@anisen](https://discuss.elastic.co/u/anisen)
#### Post date: [January 19, 2017, 9:13am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/7 "2017-01-19T09:13:58Z")

</div>

Could you please let me know how I can increase the number of workers?

I had this config:

output {  
elasticsearch {  
action =\> "index"  
hosts =\> "localhost"  
index =\> "myindex"  
workers =\> 1  
}  
}

But, increasing the number of workers to 2 or more, giving the below error message:  
"You are using a plugin that doesn't support workers but have set the workers value explicitly! This plugin uses the shared and doesn't need this option"

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [January 19, 2017, 9:50am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/8 "2017-01-19T09:50:02Z")

</div>

The Elasticsearch output in 5.1.1 apparently no longer need the workers parameter, as this is handled automatically as it is thread-safe. This could however be better documented in my opinion, so I will open an issue.

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [January 19, 2017, 9:58am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/9 "2017-01-19T09:58:56Z")

</div>

What is 10 lakh data?

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [January 19, 2017, 9:59am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/10 "2017-01-19T09:59:52Z")

</div>

What is the spec of the machine you are running Logstash on?

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [January 19, 2017, 10:00am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/11 "2017-01-19T10:00:31Z")

</div>

Are you running Elasticsearch and Logstash on the same machine?

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [January 19, 2017, 10:03am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/12 "2017-01-19T10:03:38Z")

</div>

Try anchoring your grok pattern to the beginning of the string e.g.

```ruby
grok {
  match => { "message" => '^%{DATA:timestamp} %{IPORHOST:clientip} %{NOTSPACE:method} %{NOTSPACE:uri} %{NOTSPACE:csuriquery} %{NOTSPACE:port} %{NOTSPACE:username} %{NOTSPACE:serverip} %{NOTSPACE:agent} %{NOTSPACE:referrer} %{NOTSPACE:status} %{NOTSPACE:sub_status} %{NOTSPACE:win_status} %{NOTSPACE:responsetime}' }
}

```

add a `^` to the beginning of the pattern.  
See [https://www.elastic.co/blog/do-you-grok-grok](https://www.elastic.co/blog/do-you-grok-grok)

---

<div class="post-metadata">

### Author: ![anisen](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@anisen](https://discuss.elastic.co/u/anisen)
#### Post date: [January 19, 2017, 10:06am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/13 "2017-01-19T10:06:56Z")

</div>

Yes. I'm running Elasticsearch and Logstash on the same machine, which has the below configuration:

Processor: AMD Athlon(tm) || X2 245 Processor @2.90 GHz  
RAM : 8 GB

Tried with anchoring as well, but no appreciable difference in performance.

---

<div class="post-metadata">

### Author: ![anisen](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@anisen](https://discuss.elastic.co/u/anisen)
#### Post date: [January 19, 2017, 11:52am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/14 "2017-01-19T11:52:20Z")

</div>

1 million lines of logs.

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [January 19, 2017, 12:22pm UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/15 "2017-01-19T12:22:01Z")

</div>

Are you getting events tagged with `_grokparsefailure`?

---

<div class="post-metadata">

### Author: ![anisen](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@anisen](https://discuss.elastic.co/u/anisen)
#### Post date: [January 19, 2017, 12:25pm UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/16 "2017-01-19T12:25:17Z")

</div>

I [Checked.No](http://Checked.No) failures.

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [January 19, 2017, 12:33pm UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/17 "2017-01-19T12:33:27Z")

</div>

1000000 / 2 / 60 / 60 is 138 events per second. You should be seeing ~2000 to 4000 events per second.

Try excluding Elasticsearch by using the `stdout` output with the `dots` codec.

You should see the dots stop after about 4 minutes - if so then ES is the bottleneck.

---

<div class="post-metadata">

### Author: ![anisen](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@anisen](https://discuss.elastic.co/u/anisen)
#### Post date: [January 24, 2017, 11:14am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/18 "2017-01-24T11:14:56Z")

</div>

> [@guyboertje](#):
>
> 2000 to 4000

Tried removing elasticsearch and using dots codec, it is taking 7 mins.

But, I need the data in Elasticsearch, so sending data to ES in different machine instead of localhost:

output {  
elasticsearch {  
action =\> "index"  
hosts =\> "100.100.0.10:9200"  
index =\> "myindex"  
}  
}

Still taking a lot of time (around 90 mins). Any suggestion how to improve this?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 21, 2017, 11:14am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130/19 "2017-02-21T11:14:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
