# Logstash -\> Kafka output preferred settings

**URL:** <https://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941>\
**Category:** Logstash\
**Created:** [February 16, 2016, 9:22pm UTC](https://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941 "2016-02-16T21:22:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![malonej7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/malonej7/32/6468_2.png) [@malonej7](https://discuss.elastic.co/u/malonej7)\
**Post date:** [February 16, 2016, 9:22pm UTC](https://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/1 "2016-02-16T21:22:08Z")

</div>

Are there any preferred, non-default settings for using the kafka output in logstash? Any specific Kafka-side settings that should be checked as well?

I'm running into the issue of logstash seemingly not being able to keep up with the load when all it's doing is listening on TCP (using json\_lines codec) and outputting to Kafka (snappy compression). After a few seconds to a few minutes of running smoothly, logstash "chokes" and stops processing anything. No errors, no logs, nothing. CPU drops down to almost 0.

I'm certain it's an issue with the Kafka output because if I output to File or to Elasticsearch everything works fine.

Any help would be appreciated.

Thanks,  
Jim

---

<div class="post-metadata">

**Author:** ![Joe\_Lawson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_lawson/32/3390_2.png) [@Joe\_Lawson](https://discuss.elastic.co/u/Joe_Lawson)\
**Post date:** [February 17, 2016, 12:58am UTC](https://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/2 "2016-02-17T00:58:10Z")

</div>

What version Logstash are you running? Generally the plugin uses acks = 1  
which implies that one broker acknowledges the request. If it is blocking  
on send the broker slow to respond. Perhaps trying to run a Kafka  
performance test using the Kafka tools to test for bottlenecks. How many  
logs per second are you talking about and how big?

---

<div class="post-metadata">

**Author:** ![malonej7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/malonej7/32/6468_2.png) [@malonej7](https://discuss.elastic.co/u/malonej7)\
**Post date:** [February 17, 2016, 4:31pm UTC](https://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/3 "2016-02-17T16:31:27Z")

</div>

We are running the latest logstash 2.2.1. I've tried it with acks = 0, 1, and "all" and we've run into the same issue. It now appears that the issue is that it can't handle the initial load caused by the backup of messages. We have 2 logstash instances sitting behind a load balancer which seems to queue up the messages that fail to be processed by logstash once it "chokes". So when we restart logstash and communication opens back up, we get a huge influx of messages that the kafka output can't handle (but the File and Elasticsearch plugins can) so it chokes eventually and we're back at square one.

If I get rid of the backup and only send the real-time messages, the kafka output seems to handle it fine. It's just the initial catch-up that it can't handle. But in production I can't assure that we'll never have to restart logstash or get a build-up of messages like that.

Is there an easy solution to handle this?

---

<div class="post-metadata">

**Author:** ![Joe\_Lawson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_lawson/32/3390_2.png) [@Joe\_Lawson](https://discuss.elastic.co/u/Joe_Lawson)\
**Post date:** [February 18, 2016, 5:51pm UTC](https://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/4 "2016-02-18T17:51:27Z")

</div>

Can you share your config and describe you pipeline in more detail,  
especially what is feeding Logstash? Is the load balancer queuing the  
messages as well?

I'm surprised that the process just fails to continue to deliver messages.  
When you say the file and Elasticsearch plugins can handle the restart does  
that mean you are just writing the messages to a file and removed the Kafka  
output?

The cpu consumption dropping to zero implies that the pipeline is stalled.

Maybe try 2.1.X and see if it still fails. 2.2 was a pretty significant  
release for the internal workings of Logstash.  
malonej7 [http://discuss.elastic.co/users/malonej7](http://discuss.elastic.co/users/malonej7)  
February 17

We are running the latest logstash 2.2.1. I've tried it with acks = 0, 1,  
and "all" and we've run into the same issue. It now appears that the issue  
is that it can't handle the initial load caused by the backup of messages.  
We have 2 logstash instances sitting behind a load balancer which seems to  
queue up the messages that fail to be processed by logstash once it  
"chokes". So when we restart logstash and communication opens back up, we  
get a huge influx of messages that the kafka output can't handle (but the  
File and Elasticsearch plugins can) so it chokes eventually and we're back  
at square one.

If I get rid of the backup and only send the real-time messages, the kafka  
output seems to handle it fine. It's just the initial catch-up that it  
can't handle. But in production I can't assure that we'll never have to  
restart logstash or get a build-up of messages like that.

Is there an easy solution to handle this?

Visit Topic  
[http://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/3](http://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/3)  
or reply to this email to respond  
Previous Replies  
Joe\_Lawson [http://discuss.elastic.co/users/joe\_lawson](http://discuss.elastic.co/users/joe_lawson) Logstash Plugins  
Community Maintainer  
February 17

What version Logstash are you running? Generally the plugin uses acks = 1  
which implies that one broker acknowledges the request. If it is blocking  
on send the broker slow to respond. Perhaps trying to run a Kafka  
performance test using the Kafka tools to test for bottlenecks. How many  
logs per second are you talking about and how big?

Visit Topic  
[http://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/3](http://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/3)  
or reply to this email to respond

To stop receiving notifications for this particular topic, click here  
[http://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/unsubscribe](http://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/unsubscribe).  
To unsubscribe from these emails, change your user preferences  
[http://discuss.elastic.co/my/preferences](http://discuss.elastic.co/my/preferences)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:10am UTC](https://discuss.elastic.co/t/logstash-kafka-output-preferred-settings/41941/5 "2017-07-06T05:10:50Z")

</div>


