# Logstash with heavy Syslog input

**URL:** <https://discuss.elastic.co/t/logstash-with-heavy-syslog-input/275007>\
**Category:** Logstash\
**Created:** [June 4, 2021, 9:30pm UTC](https://discuss.elastic.co/t/logstash-with-heavy-syslog-input/275007 "2021-06-04T21:30:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kfiro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kfiro/32/46872_2.png) [@Kfiro](https://discuss.elastic.co/u/Kfiro)\
**Post date:** [June 4, 2021, 9:30pm UTC](https://discuss.elastic.co/t/logstash-with-heavy-syslog-input/275007/1 "2021-06-04T21:30:05Z")

</div>

Hi friends,  
I have a SIEM system that sends 10,000 events per second to Logstash over Syslog TCP.  
It seems there is a bottleneck on logstash and i get only 1500 events per second.  
Is there a nice solution for that?

Additional data,  
Server hardware:  
14 giga RAM  
10 cpu  
100 giga Disk SSD  
Ubuntu OS

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 4, 2021, 10:28pm UTC](https://discuss.elastic.co/t/logstash-with-heavy-syslog-input/275007/2 "2021-06-04T22:28:19Z")

</div>

There answers to related questions [here](https://discuss.elastic.co/t/how-to-improve-logstash-performance-on-this-config/205138/2), [here](https://discuss.elastic.co/t/methods-to-loadbalance-on-logstash-from-input-data-stream-to-filter-section/271292/2), and [here](https://discuss.elastic.co/t/how-to-speed-up-indexing-of-csv-file-via-logstash/197785/2). Basically you will need to find the bottleneck because nobody else has visibility into your system. The [Monitoring APIs](https://www.elastic.co/guide/en/logstash/current/monitoring-logstash.html) might help. I would start by replacing your outputs with a sink output and see how much time is being spent in each plugin in the pipeline. Then do the same with whatever output you are using. See if you can scale by adding threads.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 2, 2021, 10:28pm UTC](https://discuss.elastic.co/t/logstash-with-heavy-syslog-input/275007/3 "2021-07-02T22:28:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
