# Logstash performance issues

**URL:** <https://discuss.elastic.co/t/logstash-performance-issues/327679>\
**Category:** Logstash\
**Created:** [March 14, 2023, 2:41pm UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679 "2023-03-14T14:41:05Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [March 14, 2023, 2:41pm UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/1 "2023-03-14T14:41:05Z")

</div>

Hi ,

I Have a Logstash 7.17 version , i have two logstash servers in my Setup that gets connected to a 3 node ELK Cluster. One Kibana server

We are experiencing less data getting populated in the kibana dashboards. when i look at 15 minutes interval, i see there is very less data coming up or no data coming up for the beats servers.

What might be the issue. i have increased the jvm for my logstash to 16g and the CPU and Memory is in control.

any advise will be helpful

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 14, 2023, 3:35pm UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/2 "2023-03-14T15:35:53Z")

</div>

> [@AKAM14](#):
>
> What might be the issue. i have increased the jvm for my logstash to 16g and the CPU and Memory is in control.

It is impossible to know unless you provide more context.

What is the source of the data? What does your logstash configuration looks like? Do you have anything in the logs of Logstash? Do you have anything in the logs of Filebeat?

Also, Logstash is more CPU bound than memory bound, increase the JVM for Logstash may not change anything. What is the CPU configuration of the logstash server? How many cores it have?

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [March 15, 2023, 6:29am UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/3 "2023-03-15T06:29:40Z")

</div>

We have only metric beats and winlog beats sending data to logstash servers. we have around 90 servers that are sending the data from these beats.

input {

beats {

```
port => 5044

```

}

}

output {  
if [agent][type] == "metricbeat" {  
stdout { codec =\> rubydebug }  
elasticsearch {  
hosts =\>   
user =\> logstash  
password =\> logstash  
#index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
ilm\_enabled =\> "true"  
ilm\_rollover\_alias =\> "metricbeat"  
ilm\_pattern =\> "000001"  
}  
}  
else if [agent][type] == "winlogbeat" {  
stdout { codec =\> rubydebug }  
elasticsearch {  
hosts =\>   
user =\> logstash  
password =\> logstash  
#index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
ilm\_enabled =\> "true"  
ilm\_rollover\_alias =\> "winlogbeat-7.17.3"  
ilm\_pattern =\> "000001"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [March 15, 2023, 6:33am UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/4 "2023-03-15T06:33:23Z")

</div>

The Logstash server has a Intel Xeon gold 6248 @2.50Ghz(4 core) processors and ram is 32 gb . there is enough space in the disk also.

i have increased the worker nodes to 4 and piepline batch size to 1000 and pipeline batch delay to 300ms

---

<div class="post-metadata">

**Author:** ![heikis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/heikis/32/80983_2.png) [@heikis](https://discuss.elastic.co/u/heikis)\
**Post date:** [March 15, 2023, 12:08pm UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/5 "2023-03-15T12:08:22Z")

</div>

your `index =>` is commented out (`#`). Or are you trying to use datastreams?

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [March 15, 2023, 12:35pm UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/6 "2023-03-15T12:35:30Z")

</div>

yes we have created ILM Policies and index templates .

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 15, 2023, 12:52pm UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/7 "2023-03-15T12:52:09Z")

</div>

Your pipeline is pretty simple, there is no filters that could increase the processing time.

Are you using persistent queues?

Also, most of the time when you have some indexing issues, like lags, the issue is in Elasticsearch, not Logstash.

What are your Elasticsearch configurations? CPU, Memory, Heap and Disk type for example.

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [March 16, 2023, 1:34am UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/8 "2023-03-16T01:34:09Z")

</div>

Hi,  
There is no persistent queues. we have a 3 node Elastic Search cluster . every node has Intel Xenon Gold 6248 cpu @2.50 gHZ(4 Core), Memory is 32 gb and heap is 16gb. We have a 1 TB Disk for every server.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 16, 2023, 3:17am UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/9 "2023-03-16T03:17:10Z")

</div>

> [@AKAM14](#):
>
> We have a 1 TB Disk for every server.

What is the kind of disk, it is HDD or SSD?

Also, do you have something in both Logstash and Elasticsearch logs?

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [March 16, 2023, 1:50pm UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/10 "2023-03-16T13:50:28Z")

</div>

The Disk is HDD . i Checked the logstash plain logs-- there is no errors. while in the cluster logs of ELK also i didnt find any errors.

Do i need to check any other logs in Elasticsearch, which could throw some light on the slowness or indexing issues

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2023, 1:51pm UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679/11 "2023-04-13T13:51:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
