# Logstash output send rate

**URL:** <https://discuss.elastic.co/t/logstash-output-send-rate/76277>\
**Category:** Logstash\
**Created:** [February 23, 2017, 5:31pm UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277 "2017-02-23T17:31:07Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ld\_pvl](https://avatars.discourse-cdn.com/v4/letter/l/cdc98d/32.png) [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Post date:** [February 23, 2017, 5:31pm UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277/1 "2017-02-23T17:31:07Z")

</div>

Hi Elastic Team,

Does Logstash have a feature that allows us to set how many events are sent to remotes, for example outputted to Elasticsearch, for every particular time interval?

What we are trying to do is something like this: have no more than X number of events or Y MB of data sent by Logstash every N time interval - a bit like throttling.

I still want all the events to be sent just at a controlled rate.

I've tried using the [throttle](https://www.elastic.co/guide/en/logstash/current/plugins-filters-throttle.html) plugin but am not sure whether it fits the purpose.

Cheers,

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 24, 2017, 1:52am UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277/2 "2017-02-24T01:52:35Z")

</div>

Throttle is not what you want.  
You should run 5.2 and then use the Monitoring functionality.

---

<div class="post-metadata">

**Author:** ![ld\_pvl](https://avatars.discourse-cdn.com/v4/letter/l/cdc98d/32.png) [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Post date:** [February 24, 2017, 10:37am UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277/3 "2017-02-24T10:37:31Z")

</div>

Hi Mark,

Thanks for your reply.

Maybe I've missed something but x-pack monitoring for logstash only gives me the rate values but doesn't really give me the ability to tweak the rates themselves.

Say I notice that Logstash is sending too many events per second, how can I tell Logstash to "calm down" a bit and do not exceed x amount of events per second or x MB per second.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 24, 2017, 10:40am UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277/4 "2017-02-24T10:40:56Z")

</div>

I misread that sorry.

If you are sending to ES then it'll tell LS to slow down, which it will. I don't know how to do that for other outpus.

---

<div class="post-metadata">

**Author:** ![ld\_pvl](https://avatars.discourse-cdn.com/v4/letter/l/cdc98d/32.png) [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Post date:** [February 24, 2017, 10:58am UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277/5 "2017-02-24T10:58:38Z")

</div>

Yep, I'm sending to ES.

That is interesting, I did not know that ES tells LS to slow down.

Do you have links to any of the documentations for that?

Or do you know concrete numbers like by how much ES tells LS to slow down and how it's doing that and whether it is configurable?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 25, 2017, 7:19am UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277/6 "2017-02-25T07:19:31Z")

</div>

ES dictates it all, see [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#\_retry\_policy](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#_retry_policy) for details.

---

<div class="post-metadata">

**Author:** ![ld\_pvl](https://avatars.discourse-cdn.com/v4/letter/l/cdc98d/32.png) [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Post date:** [February 28, 2017, 9:59am UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277/7 "2017-02-28T09:59:37Z")

</div>

Thanks Mark, I've checked the link but the retry policy only describes the behaviour when there is a disconnect.

I've looked further into the [adaptive throttling](https://www.elastic.co/blog/performance-indexing-2-0) feature of ES which determines the indexing/merge IO rate of ES when the load is high and when the load is low. So hypothetically, if when the load is high, the merge IO rate has been dynamically determined to be 200MB/s, does that mean roughly if I have 10 Logstash instances each of them will only be sending 20 MB/s?

And if I really wanted to, I could set `indices.store.throttle.max_bytes_per_sec` (I understand this is not recommended) explicitly that would indirectly limit the send rate of logstash during high load?

Also a side question: before sending data requests/docs to ES, does Logstash send some sort of handshake or status requests or permission requests prior to sending data to know whether or not to send the docs over to ES?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 28, 2017, 11:11am UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277/8 "2017-02-28T11:11:40Z")

</div>

If ES is too busy it will provide a 429, then the retry policy starts. That's as complicated as it gets (good or bad).

> [@ld\_pvl](#):
>
> And if I really wanted to, I could set indices.store.throttle.max\_bytes\_per\_sec (I understand this is not recommended) explicitly that would indirectly limit the send rate of logstash during high load?

No. That only applies for older versions of ES, newer versions auto throttle.

> [@ld\_pvl](#):
>
> Also a side question: before sending data requests/docs to ES, does Logstash send some sort of handshake or status requests or permission requests prior to sending data to know whether or not to send the docs over to ES?

It's a typical http connection request.

---

<div class="post-metadata">

**Author:** ![ld\_pvl](https://avatars.discourse-cdn.com/v4/letter/l/cdc98d/32.png) [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Post date:** [February 28, 2017, 11:37am UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277/9 "2017-02-28T11:37:04Z")

</div>

Many thanks Mark

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2017, 11:37am UTC](https://discuss.elastic.co/t/logstash-output-send-rate/76277/10 "2017-03-28T11:37:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
