# Logstash performance drop with high CPU usage

**URL:** <https://discuss.elastic.co/t/logstash-performance-drop-with-high-cpu-usage/53691>\
**Category:** Logstash\
**Created:** [June 22, 2016, 4:49pm UTC](https://discuss.elastic.co/t/logstash-performance-drop-with-high-cpu-usage/53691 "2016-06-22T16:49:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nitesh\_Jain](https://avatars.discourse-cdn.com/v4/letter/n/ecccb3/32.png) [@Nitesh\_Jain](https://discuss.elastic.co/u/Nitesh_Jain)\
**Post date:** [June 22, 2016, 4:49pm UTC](https://discuss.elastic.co/t/logstash-performance-drop-with-high-cpu-usage/53691/1 "2016-06-22T16:49:41Z")

</div>

Hi,  
CPU usage spiked up to 3000% with the load of the box being around 400. There was no config change. This is also causing messages to pile up in the queues

This is my setup:  
rsyslog -\> logstash -\> rabbitmq -\> logstash -\> elasticsearch

This is the filter:  
grok {  
match =\> ["message", "\<%{POSINT:syslog\_pri}\>%{SYSLOGTIMESTAMP:time\_extra}\s+%{DATA:hostname}\s+%{DATA:type\_extra}:\s+%{SYSLOGTIMESTAMP:time}\s+[%{DATA:tomcat\_instance}]\s+%{DATA:log\_type}\s+%{DATA:servlet}\s+-\s+(uuid%{DATA:uuid}|)?%{IP:ip\_address}|%{DATA:origin}|%{DATA:db\_server}|%{DATA:path}|%{DATA:call\_type}|%{NUMBER:TotalTime:float}|%{NUMBER:CpuTime:float}|%{NUMBER:DbTime:float}|%{NUMBER:NetworkTime:float}(|%{NUMBER:KEY\_1}|%{NUMBER:VALUE\_1})?(|%{NUMBER:KEY\_2}|%{NUMBER:VALUE\_2})?(|%{NUMBER:KEY\_3}|%{NUMBER:VALUE\_3})?(|%{NUMBER:KEY\_4}|%{NUMBER:VALUE\_4})?(|%{NUMBER:KEY\_5}|%{NUMBER:VALUE\_5})?(|%{NUMBER:KEY\_6}|%{NUMBER:VALUE\_6})?(|%{NUMBER:KEY\_7}|%{NUMBER:VALUE\_7})?(|%{NUMBER:KEY\_8}|%{NUMBER:VALUE\_8})?(|%{NUMBER:KEY\_9}|%{NUMBER:VALUE\_9})?(|%{NUMBER:KEY\_10}|%{NUMBER:VALUE\_10})?(|%{NUMBER:KEY\_11}|%{NUMBER:VALUE\_11})?(|%{NUMBER:KEY\_12}|%{NUMBER:VALUE\_12})?(|%{NUMBER:KEY\_13}|%{NUMBER:VALUE\_13})?(|%{NUMBER:KEY\_14}|%{NUMBER:VALUE\_14})?(|%{NUMBER:KEY\_15}|%{NUMBER:VALUE\_15})?(|%{NUMBER:KEY\_16}|%{NUMBER:VALUE\_16})?(|%{NUMBER:KEY\_17}|%{NUMBER:VALUE\_17})?(|%{NUMBER:KEY\_18}|%{NUMBER:VALUE\_18})?(|%{NUMBER:KEY\_19}|%{NUMBER:VALUE\_19})?(|%{NUMBER:KEY\_20}|%{NUMBER:VALUE\_20})?(|%{NUMBER:KEY\_21}|%{NUMBER:VALUE\_21})?(|%{NUMBER:KEY\_22}|%{NUMBER:VALUE\_22})?(|%{NUMBER:KEY\_23}|%{NUMBER:VALUE\_23})?(|%{NUMBER:KEY\_24}|%{NUMBER:VALUE\_24})?(|%{NUMBER:KEY\_25}|%{NUMBER:VALUE\_25})?(|%{NUMBER:KEY\_26}|%{NUMBER:VALUE\_26})?(|%{NUMBER:KEY\_27}|%{NUMBER:VALUE\_27})?(|%{NUMBER:KEY\_28}|%{NUMBER:VALUE\_28})?(|%{NUMBER:KEY\_29}|%{NUMBER:VALUE\_29})?(|%{NUMBER:KEY\_30}|%{NUMBER:VALUE\_30})?(|%{NUMBER:KEY\_31}|%{NUMBER:VALUE\_31})?(|%{NUMBER:KEY\_32}|%{NUMBER:VALUE\_32})?(|%{NUMBER:KEY\_33}|%{NUMBER:VALUE\_33})?(|%{NUMBER:KEY\_34}|%{NUMBER:VALUE\_34})?(|%{NUMBER:KEY\_35}|%{NUMBER:VALUE\_35})?(|%{NUMBER:KEY\_36}|%{NUMBER:VALUE\_36})?(|%{NUMBER:KEY\_37}|%{NUMBER:VALUE\_37})?(|%{NUMBER:KEY\_38}|%{NUMBER:VALUE\_38})?(|%{NUMBER:KEY\_39}|%{NUMBER:VALUE\_39})?(|%{NUMBER:KEY\_40}|%{NUMBER:VALUE\_40})?(|%{WORD:tag\_1}|%{WORD:tag\_data}|%{WORD:tag\_2}|%{WORD:first\_tag\_data}|%{WORD:tag\_3}|%{WORD:or\_of\_test})?" ]  
remove\_field =\> ["time\_extra", "type\_extra"]

The CPU usage was with a single instance of logstash running. My production version of logstash is 1.4. Tried with the latest version too and saw the same thing happening.

Can someone help with this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 4, 2016, 6:28pm UTC](https://discuss.elastic.co/t/logstash-performance-drop-with-high-cpu-usage/53691/2 "2016-07-04T18:28:55Z")

</div>

You can't use a csv filter for this? Or at least the final KEY\_nn parts.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:49am UTC](https://discuss.elastic.co/t/logstash-performance-drop-with-high-cpu-usage/53691/3 "2017-07-06T04:49:42Z")

</div>


