# Logstash JMS plugin extremly slow

**URL:** <https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210>\
**Category:** Logstash\
**Created:** [March 26, 2024, 9:53pm UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210 "2024-03-26T21:53:12Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Oussama\_seif\_eddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oussama_seif_eddine/32/133009_2.png) [@Oussama\_seif\_eddine](https://discuss.elastic.co/u/Oussama_seif_eddine)\
**Post date:** [March 26, 2024, 9:53pm UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210/1 "2024-03-26T21:53:12Z")

</div>

Hello,  
I'm using Logstash JMS plugin to connect to an EMS server and fetch data from a queue.  
I output then to my elastic cluster (2 nodes).  
The issue is that even i have a lot of consumers (300 thread/logstach server and 3 servers), the queue consumption is very slow.  
I tried to change the output, and put file output instead of elasticsearch, and the consumption is very fast, i managed to consume all data using only one logstash node.  
Any ideas on how i can troubleshoot this issue ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 26, 2024, 10:04pm UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210/2 "2024-03-26T22:04:33Z")

</div>

> [@Oussama\_seif\_eddine](#):
>
> I tried to change the output, and put file output instead of elasticsearch, and the consumption is very fast, i managed to consume all data using only one logstash node.

This suggests that Elasticsearch is your bottleneck and not Logstash.

What are the specs of your Elasticsearch nodes? Like, CPU, Memory, Disk type (SSD or HDD?)

Do you have a mapping or are using dynamic mapping? This [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-indexing-speed.html) has some tips on how to tune elasticsearch for indexing speed.

Also, did you change the values of `pipeline.batch.size` for your logstash pipeline? This can also impact on the performance, but in this case it seems that the main bottleneck is Elasticsearch.

---

<div class="post-metadata">

**Author:** ![Oussama\_seif\_eddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oussama_seif_eddine/32/133009_2.png) [@Oussama\_seif\_eddine](https://discuss.elastic.co/u/Oussama_seif_eddine)\
**Post date:** [March 26, 2024, 10:22pm UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210/3 "2024-03-26T22:22:41Z")

</div>

Hello @leandrojmp and thanks for the quick answer.  
for my elastic nodes, i have 16Gb memory, 8 cores and a mounted share HDD.  
And here my conf file

```auto
input {
    jms {
        include_headers => false
        include_properties => false
        include_body => true
        use_jms_timestamp => false
        interval => 5
        destination => "bwpm.event"
        threads => "300"
        yaml_file => "/monitoring/logstash/logstash-8.12.2/config/ems/jms.yml"
        yaml_section => "jms"
    }
}

filter {
    xml {
        source => "message"
        remove_namespaces => true
        store_xml => false
        target => "pasred_xml"
        xpath => [
            "/LogMessage/LogID/text()", "LogID",
            "/LogMessage/CorrelationLogID/text()", "CorrelationLogID",
                        "/LogMessage/JobID/text()", "JobID",
                        "/LogMessage/DomainName/text()", "DomainName",
                        "/LogMessage/MachineName/text()", "MachineName",
                        "/LogMessage/EngineName/text()", "EngineName",
                        "/LogMessage/Deployment/text()", "Deployment",
                        "/LogMessage/ProcessName/text()", "ProcessName",
                        "/LogMessage/JobStart/text()", "JobStart",
                        "/LogMessage/JobEnd/text()", "JobEnd",
                        "/LogMessage/Status/text()", "Status",
                        "/LogMessage/Events/Event[1]/Attributes/Attribute[not (contains(Name,'ransaction'))]/Value/text()", "MainInput",
                       "/LogMessage/Events/Event[1]/Attributes/Attribute[contains(Name,'ransaction')]/Value/text()", "TransactionID",
                        "/LogMessage/Events/Event/Attributes/Attribute/Value/text()", "Attributes",
                        "/LogMessage/Events/Event[1]/Payload/text()", "Request_Payload",
                        "/LogMessage/Events/Event[2]/Payload/text()", "Response_Payload",
                        "/LogMessage/Events/Event[1]/Attributes/Attribute[contains(Name,'USER')]/Value/text()","userName",
                        "/LogMessage/Events/Event[1]/Attributes/Attribute[contains(Name,'Adresse')]/Value/text()","IPaddr",
                       "/LogMessage/Events/Event/EventMsg/text()", "EventMsg",
                       "/LogMessage/Events/Event/EventMsgCode/text()", "EventMsgCode",
                       "/LogMessage/Events/Event[ActivityName = 'LogError']/EventMsgCode/text()", "FailureMsgCode",
                       "/LogMessage/Events/Event/Stacktrace/text()", "StackTrace",
                        "/LogMessage/Track/Transition/text()", "Transitions",
                        "/LogMessage/Track/*", "CompleteTrack",
                        "sum (/LogMessage/Track/Transition/@ElapsedTime)", "ElapsedTime(ms)"
        ]
    }

    mutate {
            remove_field => ["message"]
            remove_field => ["pasred_xml"]
            gsub => [
                "Request_Payload", "&lt;", "<",
                "Request_Payload", "&gt;", ">",
                "Response_Payload", "&lt;", "<",
                "Response_Payload", "&gt;", ">",
                "StackTrace", "&lt;", "<",
                "StackTrace", "&gt;", ">",
                "Status", "1", "OK",
                "Status", "2", "KO",
                "Status", "3", "KO"

                    ]
           convert => {
               "ElapsedTime(ms)" => "integer"
                   }

        }
}

output {
elasticsearch{
                hosts => ["https://xxxx:9200","https://xxxx:9200"]
                index => "pm-elk-%{+YYYY-MM-dd_hh:mm}"
                user => "elastic"
                password => "HbbrE-UaR3oQFcht9LjM"
                ilm_rollover_alias => "pm-elk"
                ssl => true
                cacert => "/monitoring/logstash/logstash-8.12.2/config/certs/http_ca.crt"
                validate_after_inactivity => 0
        }

}

```

Also for some reason, the index part is not being taken into consideration, the default index is being created.  
Note that i have a very large amount of data to handle (written in a file, i had 6GB of data/minute in busy hours)

---

<div class="post-metadata">

**Author:** ![Oussama\_seif\_eddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oussama_seif_eddine/32/133009_2.png) [@Oussama\_seif\_eddine](https://discuss.elastic.co/u/Oussama_seif_eddine)\
**Post date:** [March 27, 2024, 3:10pm UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210/4 "2024-03-27T15:10:32Z")

</div>

Refreshing this topic

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 27, 2024, 3:59pm UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210/5 "2024-03-27T15:59:56Z")

</div>

Hello, please avoid bumping posts when less then 24 hours have passed

> [@Oussama\_seif\_eddine](#):
>
> mounted share HDD

This may be your issue, HDD is bad for performance, not sure you will be able to improve this without changing to SSD.

> [@leandrojmp](#):
>
> Also, did you change the values of `pipeline.batch.size` for your logstash pipeline?

You didn't answer that, I'm assuming you didn't change this setting.

Try increasing `pipeline.batch.size` in your `logstash.yml` or `pipelines.yml`, depends on where you are setting your pipeline.

The default value is `125`, increase it and see if anything changes, like teste with `250`, then `500`.

You may need to restart logstash for the changes to work.

Also, did you check the documetation about tuning elasticsearch for indexing speed? There are some hints there of things that you may try to see if this improve.

---

<div class="post-metadata">

**Author:** ![Oussama\_seif\_eddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oussama_seif_eddine/32/133009_2.png) [@Oussama\_seif\_eddine](https://discuss.elastic.co/u/Oussama_seif_eddine)\
**Post date:** [March 27, 2024, 8:49pm UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210/6 "2024-03-27T20:49:31Z")

</div>

Hello,  
Thanks a lot for the recommandations, and sorry for the spam.  
I am trying to follow the recommandations to optimize.  
I’ll also check the indexing part, maybee there’s an issue there also.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 28, 2024, 9:10am UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210/7 "2024-03-28T09:10:50Z")

</div>

Few more tips:

- Check LS [API statistics](https://www.elastic.co/guide/en/logstash/current/node-stats-api.html): [http://localhost:9600/\_node/stats/pipelines?pretty](http://localhost:9600/_node/stats/pipelines?pretty)
- How many GB RAM do you have on LS? The XML plugin use more then usual plugins like Grok.
- Have you check LS logs, is there any trace?
- If you are using the persistent queue, switch to the memory queue
- Have tried to enable `compression_level`?
- Have you tried to send data only to 1 node? Test the connection per every single node. Data shouldn't be sent to master nodes
- Check can `pool_max` and `pool_max_per_route` help to speedup the network connection. Also check again is good to set `validate_after_inactivity` =0, maybe is better 100 ms

On ES side:

- You have the ES cluster with two nodes, maybe you have the internal ES issue like split brain
- Have you check ES logs? Anything there?
- Do you have any issue with the cluster or shards? Check [the trouble. documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/fix-common-cluster-issues.html).
- Have you tried to send data to a single node without ILM, no replica?

---

<div class="post-metadata">

**Author:** ![Oussama\_seif\_eddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oussama_seif_eddine/32/133009_2.png) [@Oussama\_seif\_eddine](https://discuss.elastic.co/u/Oussama_seif_eddine)\
**Post date:** [March 28, 2024, 9:23pm UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210/8 "2024-03-28T21:23:14Z")

</div>

Hello  
Thanks all for the great helping tips, i managed to figure this out, the issue actually was the disk on elastic, i was using a NAS and having very bad network quality, so data trasnfert was taking too long, i switched to local disks and now everything is running smoothly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2024, 9:23pm UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210/9 "2024-04-25T21:23:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
