# Logstash Sizing

**URL:** <https://discuss.elastic.co/t/logstash-sizing/83065>\
**Category:** Logstash\
**Created:** [April 20, 2017, 1:50pm UTC](https://discuss.elastic.co/t/logstash-sizing/83065 "2017-04-20T13:50:53Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [April 20, 2017, 1:50pm UTC](https://discuss.elastic.co/t/logstash-sizing/83065/1 "2017-04-20T13:50:53Z")

</div>

What is the recommended typical sizing configuration with respect to memory, disk and cpu for logstash.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 20, 2017, 2:07pm UTC](https://discuss.elastic.co/t/logstash-sizing/83065/2 "2017-04-20T14:07:27Z")

</div>

That depends on how long your rope is.

Jokes aside:

- The CPU needs depend on how many events per second you're going to processs.
- 1-2 GB RAM should be plenty.
- Logstash persists very little information to disk by itself, so you basically only need space for the program files and the log files it produces.

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [April 20, 2017, 6:25pm UTC](https://discuss.elastic.co/t/logstash-sizing/83065/3 "2017-04-20T18:25:54Z")

</div>

Thanks. Around 100 million documents per day.we are considering 3 logstash nodes reading from kafka.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 21, 2017, 5:20am UTC](https://discuss.elastic.co/t/logstash-sizing/83065/4 "2017-04-21T05:20:05Z")

</div>

100M events/day is only about 1200 events/second. Your events will probably not be evenly distributed over the day so in reality I guess you'll have to deal with higher loads. On the other hands, with Kafka as a buffer you'll be able to cope with spikes just fine assuming you can live with latency in downstream event delivery.

A single-core machine can process hundreds of events per second so three machines can probably handle your load just fine. But don't take my word for it; measure yourself with the filters that you're going to use.

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [April 21, 2017, 9:05am UTC](https://discuss.elastic.co/t/logstash-sizing/83065/5 "2017-04-21T09:05:33Z")

</div>

Sure. Thank you. This is very helpful.

---

<div class="post-metadata">

**Author:** ![bhatch](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@bhatch](https://discuss.elastic.co/u/bhatch)\
**Post date:** [April 21, 2017, 3:49pm UTC](https://discuss.elastic.co/t/logstash-sizing/83065/6 "2017-04-21T15:49:16Z")

</div>

The filters you have setup can heavily change your requirements.  
We have some with logstash configurations that are hundreds of lines long. Lots of mutate, grok, and other expensive operations. Those 4 core machines can only do 2500 events per second. But we have other 4 core machines with almost no filters and they can do at least 4 or 5 times that amount.

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [April 24, 2017, 11:19am UTC](https://discuss.elastic.co/t/logstash-sizing/83065/7 "2017-04-24T11:19:27Z")

</div>

Thanks Brandon for the additional information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2017, 11:24am UTC](https://discuss.elastic.co/t/logstash-sizing/83065/8 "2017-05-22T11:24:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
