# (Logstash newbie) Logstash 5.0. 150k flows/min limit

**URL:** <https://discuss.elastic.co/t/logstash-newbie-logstash-5-0-150k-flows-min-limit/65690>\
**Category:** Logstash\
**Created:** [November 10, 2016, 3:20pm UTC](https://discuss.elastic.co/t/logstash-newbie-logstash-5-0-150k-flows-min-limit/65690 "2016-11-10T15:20:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Simon2](https://avatars.discourse-cdn.com/v4/letter/s/d26b3c/32.png) [@Simon2](https://discuss.elastic.co/u/Simon2)\
**Post date:** [November 10, 2016, 3:20pm UTC](https://discuss.elastic.co/t/logstash-newbie-logstash-5-0-150k-flows-min-limit/65690/1 "2016-11-10T15:20:44Z")

</div>

Hello. I just started using Logstash 5, but I am stuck, and cannot figure out why.  
So if anybody have any idea/suggestions please let me know.

I use Logstash to capture netflow V9 from UDP ports and forward it towards my Elasticsearch cluster.

In my setup I have two identical Logstash nodes running 2.4.0, that each collect around 1.6mil flows/min.  
I installed Logstash 5 on one of them, and configured both the config file, jvm.options and logstash.yml, but for some reason hit a 150k flows/min roof.  
I can see from htop that Logstash are able to allocate 50g memory, but the CPU cores are mostly idle.

From having the same setting as the other Logstash node, I have been scaling individually on everything I could find, with no luck.

From another post i saw something about number of open files, but since my setup reads from an UDP port, I figured that it might not be it.

I myself think the problem was with the number of workers or number of workers/batch size(and delay), but changes on them have shown no effect.  
So I must be missing something.

Ideas?  
Best regards Simon.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 11, 2016, 10:00am UTC](https://discuss.elastic.co/t/logstash-newbie-logstash-5-0-150k-flows-min-limit/65690/2 "2016-11-11T10:00:50Z")

</div>

What's your config look like?  
What OS?  
What are the nodes specs?

---

<div class="post-metadata">

**Author:** ![Simon2](https://avatars.discourse-cdn.com/v4/letter/s/d26b3c/32.png) [@Simon2](https://discuss.elastic.co/u/Simon2)\
**Post date:** [November 16, 2016, 9:09am UTC](https://discuss.elastic.co/t/logstash-newbie-logstash-5-0-150k-flows-min-limit/65690/3 "2016-11-16T09:09:09Z")

</div>

Config:  
.conf:  
input { udp {  
port =\> xxxx  
codec =\> netflow {  
versions =\> [9]  
}}}  
output { elasticsearch {  
hosts =\> ["x.x.x.x","x.x.x.x"]  
index =\> "logstash-%{+YYYY.MM.dd.HH}"  
}  
}

logstash.yml: (  
[node.name](http://node.name): logstash  
path.data: /var/lib/logstash  
pipeline.workers: 112  
pipeline.output.workers: 56  
pipeline.batch.size: 4000  
pipeline.batch.delay: 1  
path.logs: /var/log/logstash

jvm.options:  
-Xms62g  
-Xmx62g

Rest of the config is default Logstash config.

OS  
Debian "jessie" 8.6

Logstash node spec  
RAM: 74 GB  
CPU: 56 cores, 2.4 GHz

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 16, 2016, 9:30am UTC](https://discuss.elastic.co/t/logstash-newbie-logstash-5-0-150k-flows-min-limit/65690/4 "2016-11-16T09:30:54Z")

</div>

The number of [worker threads](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-udp.html#plugins-inputs-udp-workers) in the UDP input plugin defaults to 2, and since you are using the netflow codec, which does a fair bit of processing, I would recommend trying to increase this. I would probably also reduce the number of pipeline workers and align this with the output workers.

---

<div class="post-metadata">

**Author:** ![Simon2](https://avatars.discourse-cdn.com/v4/letter/s/d26b3c/32.png) [@Simon2](https://discuss.elastic.co/u/Simon2)\
**Post date:** [November 16, 2016, 12:44pm UTC](https://discuss.elastic.co/t/logstash-newbie-logstash-5-0-150k-flows-min-limit/65690/5 "2016-11-16T12:44:34Z")

</div>

That worked 🙂 many thanks. I removed the workers, queue\_size and flush\_size from the config file at installation due the changing to 5.0, but i should have had let the workers stayed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2016, 12:45pm UTC](https://discuss.elastic.co/t/logstash-newbie-logstash-5-0-150k-flows-min-limit/65690/6 "2016-12-14T12:45:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
