# Logstash JVM heap and GC issues

**URL:** <https://discuss.elastic.co/t/logstash-jvm-heap-and-gc-issues/120711>\
**Category:** Logstash\
**Created:** [February 20, 2018, 6:55pm UTC](https://discuss.elastic.co/t/logstash-jvm-heap-and-gc-issues/120711 "2018-02-20T18:55:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gorizon](https://avatars.discourse-cdn.com/v4/letter/g/bbe5ce/32.png) [@gorizon](https://discuss.elastic.co/u/gorizon)\
**Post date:** [February 20, 2018, 6:55pm UTC](https://discuss.elastic.co/t/logstash-jvm-heap-and-gc-issues/120711/1 "2018-02-20T18:55:22Z")

</div>

Hi I've got an issue with my JVM heap steadily increasing until all the space is used up.

Seems that the garbage collection is removing less and less space until eventually the heap is used up.  
Here is a picture of what's going on.

 ![Heap%20issues](https://us1.discourse-cdn.com/elastic/original/3X/a/f/af4db998bcbafa174c551bb776d2a613387b66e6.PNG)

This is a small test lab environment to familiarize myself with the ins and outs of the ELK stack.

Here is my configuration files for reference.

Pipe 1

> input {  
> beats {  
> port =\> 5043  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> ["[http://10.1.1.22:9200](http://10.1.1.22:9200)"]  
> index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> }  
> }

Pipe 2

> input {  
> udp {  
> port =\> 9996  
> codec =\> netflow {  
> versions =\> [5, 9]  
> }  
> type =\> netflow  
> tags =\> "port\_9996"  
> }  
> udp {  
> port =\> 9995  
> codec =\> netflow {  
> versions =\> [5, 9]  
> }  
> type =\> netflow  
> tags =\> "port\_9995"  
> }  
> }  
> output {  
> if "port\_9996" in [tags] {  
> elasticsearch {  
> hosts =\> ["10.1.1.22:9200"]  
> index =\> "logstash-netflow-9996-%{+YYYY.MM.dd}"  
> }  
> } else if "port\_9995" in [tags] {  
> elasticsearch {  
> hosts =\> ["10.1.1.22:9200"]  
> index =\> "logstash-netflow-9995-%{+YYYY.MM.dd}"  
> }  
> }  
> }

Pipe 3

> input {  
> beats {  
> port =\> 5044  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> ["[http://10.1.1.22:9200](http://10.1.1.22:9200)"]  
> index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> }  
> }

All components are of the lastest version, all running on Openjdk 1.8. as well as x-pack basic.

Logstash is running on it's own VM with Elastic and Kibana on another.

Any help is greatly appreciated!

---

<div class="post-metadata">

**Author:** ![gorizon](https://avatars.discourse-cdn.com/v4/letter/g/bbe5ce/32.png) [@gorizon](https://discuss.elastic.co/u/gorizon)\
**Post date:** [February 20, 2018, 10:30pm UTC](https://discuss.elastic.co/t/logstash-jvm-heap-and-gc-issues/120711/2 "2018-02-20T22:30:42Z")

</div>

Found what seems to be the cause of a memory leak.

The pipeline I've setup for winlogbeat seems to be what is causing the issues here.

Netflows + metricbeat function fine.

Winlogbeat causes logstash to have issues dumping memory in garbage collection. Perhaps there is some kind of optimization/configuration I can change to adjust to fix the garbage collection?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2018, 10:30pm UTC](https://discuss.elastic.co/t/logstash-jvm-heap-and-gc-issues/120711/3 "2018-03-20T22:30:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
