I have Elasticsearch, Logstash running on a m3.xlarge.
I am trying to index 3 months log data into ELK, but after some time I see
that kernel is killing the processes because of an OOM error.
I looked at the memory metrics, which was constant around 70% (with 50%
mlocked by ES).
After few minutes of starting logstash, OOM kills ES.
I noticed that /tmp/logstash size is 5.5 GB. logstash ran fine for some
time when I first started indexing.
Is logstash trying to bulk index all these files?
How do I avoid this? can I throttles this some how? If I change this
temporary location, will that be of any help?
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to email@example.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/f25c3ec4-8343-4bc9-ba73-e37eb16413f7%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.