# Logstash OutOfMemoryError

**URL:** <https://discuss.elastic.co/t/logstash-outofmemoryerror/45265>\
**Category:** Logstash\
**Created:** [March 23, 2016, 5:30pm UTC](https://discuss.elastic.co/t/logstash-outofmemoryerror/45265 "2016-03-23T17:30:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![yammy](https://avatars.discourse-cdn.com/v4/letter/y/9fc29f/32.png) [@yammy](https://discuss.elastic.co/u/yammy)\
**Post date:** [March 23, 2016, 5:30pm UTC](https://discuss.elastic.co/t/logstash-outofmemoryerror/45265/1 "2016-03-23T17:30:52Z")

</div>

I've just started using logstash 2.2.2 with 3 hosts uploading a combined average of 20,000 events per day. Using Filebeat 1.1 to forward events. Typically after about 12 hours I will get the OutOfMemoryError in the logstash log. I've increased the HEAP size to 2GB and it tends to last a little more than 24 hours.

What is a typical logstash heap size and where is the best place to start troubleshooting this?

---

<div class="post-metadata">

**Author:** ![jupp](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jupp](https://discuss.elastic.co/u/jupp)\
**Post date:** [March 23, 2016, 7:39pm UTC](https://discuss.elastic.co/t/logstash-outofmemoryerror/45265/2 "2016-03-23T19:39:06Z")

</div>

Can you provide your logstash-config? What are you startup parameters (filterworker, batch-size)?

Maybe you can start Logstash with jmx-parameters to analyze the Memory-Usage.

---

<div class="post-metadata">

**Author:** ![yammy](https://avatars.discourse-cdn.com/v4/letter/y/9fc29f/32.png) [@yammy](https://discuss.elastic.co/u/yammy)\
**Post date:** [April 6, 2016, 6:00pm UTC](https://discuss.elastic.co/t/logstash-outofmemoryerror/45265/3 "2016-04-06T18:00:00Z")

</div>

I have copied the output statement below. It turns out to be related to using an IF statement in the output section of logstash. I wanted to have separate indexes based on the source type (set as a the prefix "myapp"), however when this put in place, I get what appears to be a memory leak. When I remove this and go with a static index name, logstash does not run out of memory.

Is there a better way to separate indexes based on type?

if [type] =~ /^myapp-/ {  
elasticsearch {  
hosts =\> ["localhost"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "myapp-filebeat-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
else {  
elasticsearch {  
hosts =\> ["localhost"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![jupp](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jupp](https://discuss.elastic.co/u/jupp)\
**Post date:** [April 6, 2016, 7:38pm UTC](https://discuss.elastic.co/t/logstash-outofmemoryerror/45265/4 "2016-04-06T19:38:05Z")

</div>

I think it's the sniffing-parameter:

> <https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/392>
>
> Hi,
> I run few instances of logstash, since upgrade to 2.2.2 i started to noti…ce permanent crashes caused by OOM errors. Bigger heap only increase interval between OOMs. I checked heap dump and found excessive amount of \*\*org.apache.http.config.Registry\*\* objects. 
> 
> Out of 3GB I had 887000 Registries taking 1.4GB of memory.
> !\[screen shot 2016-03-14 at 8 39 01 am\](https://cloud.githubusercontent.com/assets/7383511/13737791/3f454496-e9c0-11e5-9769-e9a9f8f2f614.png)
> 
> I started to monitory tenured memory utilization and amount of Registries object instances on the heap for each logstash instance.
> 
> \*\*Number of Registry objects 1GB heap (jmap -gchisto)\*\*
> 
> !\[screen shot 2016-03-14 at 8 38 16 am\](https://cloud.githubusercontent.com/assets/7383511/13738001/e4b23c12-e9c1-11e5-8633-f85277803fa8.png)
> 
> \*\*Tenured memory utilization 1GB heap (jstat -gcutil)\*\*
> !\[screen shot 2016-03-14 at 8 41 41 am\](https://cloud.githubusercontent.com/assets/7383511/13738006/eeda75e2-e9c1-11e5-881f-bb92323e24d8.png)
> 
> Drops from 85% to few percent indicate watchdog killed process as there was no point to waste CPU due to CMS cycles as memory won't be recycled.
> 
> You may notice one series of data on those screenshots that looks pretty fine, that's instance with sniffing set to false, all others had sniffing =\> true
> 
> Once disabled sniffing on all instances the problem is gone.
> 
> \*\*Disabled Sniffing: Number of Registry objects 1GB heap (jmap -gchisto)\*\*
> !\[screen shot 2016-03-14 at 8 54 32 am\](https://cloud.githubusercontent.com/assets/7383511/13738066/67883a6a-e9c2-11e5-9961-4beacc47c148.png)

> This has been fixed in version 2.5.3.Many thanks to @jsvd and @cheald.

> To install this you can do:

> bin/plugin install --version 2.5.3 logstash-output-elasticsearch

---

<div class="post-metadata">

**Author:** ![yammy](https://avatars.discourse-cdn.com/v4/letter/y/9fc29f/32.png) [@yammy](https://discuss.elastic.co/u/yammy)\
**Post date:** [April 16, 2016, 12:31pm UTC](https://discuss.elastic.co/t/logstash-outofmemoryerror/45265/5 "2016-04-16T12:31:03Z")

</div>

After upgrading logstash, all is well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:01am UTC](https://discuss.elastic.co/t/logstash-outofmemoryerror/45265/6 "2017-07-06T05:01:58Z")

</div>


