# Memory usage is at extreme high level

**URL:** <https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [September 4, 2019, 5:35pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085 "2019-09-04T17:35:52Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 4, 2019, 5:35pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/1 "2019-09-04T17:35:52Z")

</div>

Hello World!

`Memory` usage seems a bit excessive for metricbeat, is it not? I

```
# systemctl status metricbeat.service 
● metricbeat.service - Metricbeat is a lightweight shipper for metrics.
   Loaded: loaded (/lib/systemd/system/metricbeat.service; enabled; vendor preset: enabled)
   Active: active (running) since Wed 2019-09-04 16:27:07 UTC; 6h ago
     Docs: https://www.elastic.co/products/beats/metricbeat
 Main PID: 30807 (metricbeat)
    Tasks: 50 (limit: 4915)
   Memory: 4.7G
      CPU: 19h 9min 10.908s
   CGroup: /system.slice/metricbeat.service
           └─30807 /usr/share/metricbeat/bin/metricbeat -c /etc/metricbeat/metricbeat.yml -path.home /usr/share/metricbeat -path.config /etc/metricbeat -path.data /var/lib/metricbeat -path.logs /var/log/metricbeat

Sep 04 16:27:07 app11 systemd[1]: Started Metricbeat is a lightweight shipper for metrics..
# systemctl status filebeat.service 
● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch.
   Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; vendor preset: enabled)
   Active: active (running) since Tue 2019-09-03 06:08:46 UTC; 1 day 11h ago
     Docs: https://www.elastic.co/products/beats/filebeat
 Main PID: 8464 (filebeat)
    Tasks: 25 (limit: 4915)
   Memory: 22.0M
      CPU: 7min 1.198s
   CGroup: /system.slice/filebeat.service
           └─8464 /usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat

Sep 03 06:08:46 app11 systemd[1]: Started Filebeat sends log files to Logstash or directly to Elasticsearch..
# 

```

another system similar to first...

```
# systemctl status metricbeat.service 
● metricbeat.service - Metricbeat is a lightweight shipper for metrics.
   Loaded: loaded (/lib/systemd/system/metricbeat.service; enabled; vendor preset: enabled)
   Active: active (running) since Mon 2019-09-02 21:21:21 UTC; 1 day 20h ago
     Docs: https://www.elastic.co/products/beats/metricbeat
 Main PID: 14947 (metricbeat)
    Tasks: 31 (limit: 4915)
   Memory: 97.4M
      CPU: 12h 52min 42.526s
   CGroup: /system.slice/metricbeat.service
           └─14947 /usr/share/metricbeat/bin/metricbeat -c /etc/metricbeat/metricbeat.yml -path.home /usr/share/metricbeat -path.config /etc/metricbeat -path.data /var/lib/metricbeat -path.logs /var/log/metricbeat

Sep 02 21:21:21 app12 systemd[1]: Started Metricbeat is a lightweight shipper for metrics..
# systemctl status filebeat.service 
● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch.
   Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; vendor preset: enabled)
   Active: active (running) since Mon 2019-09-02 21:21:14 UTC; 1 day 20h ago
     Docs: https://www.elastic.co/products/beats/filebeat
 Main PID: 14721 (filebeat)
    Tasks: 26 (limit: 4915)
   Memory: 17.1M
      CPU: 1min 29.320s
   CGroup: /system.slice/filebeat.service
           └─14721 /usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat

Sep 02 21:21:14 app12 systemd[1]: Started Filebeat sends log files to Logstash or directly to Elasticsearch..
# 

```

Please advise.

---

<div class="post-metadata">

**Author:** ![Michael\_Madden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_madden/32/46640_2.png) [@Michael\_Madden](https://discuss.elastic.co/u/Michael_Madden)\
**Post date:** [September 4, 2019, 6:33pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/2 "2019-09-04T18:33:22Z")

</div>

Hello,

Thanks for reaching about memory usage of metricbeat. Which version of metricbeat are you running? I found a similar post that details memory issues on 7.1.x releases. The issue in the original post looks like it was fixed with the 7.2.x release.

> [@Unusually high Metricbeat memory usage](https://discuss.elastic.co/t/unusually-high-metricbeat-memory-usage/184621):
>
> I have metricbeat installed on a Windows Server 2016 Datacenter server that also has an Elasticsearch node. I also have metricbeat installed on a Windows Server 2012 Standard server with an Elasticsearch node as well in the same Elasticsearch cluster as the 2016 server. Both on Elastic Stack 7.1.1. Only the system module is enabled and configured identically on both servers: # Module: system # Docs: https://www.elastic.co/guide/en/beats/metricbeat/7.1/metricbeat-module-system.html - module:…

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 4, 2019, 10:35pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/3 "2019-09-04T22:35:06Z")

</div>

```
# metricbeat version
metricbeat version 6.8.2 (amd64), libbeat 6.8.2 [0ffbeab5a52fa93586e4178becf1252e6a837028 built 2019-07-24 14:33:55 +0000 UTC]
#

```

memory usage gets a little out of the hand (upwards `1G` between hourly restarts), so meanwhile I did following "workaround" :

```
# crontab -l | tail -1
@hourly /bin/systemctl restart metricbeat.service
#
```

---

<div class="post-metadata">

**Author:** ![Alex\_Kristiansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_kristiansen/32/46086_2.png) [@Alex\_Kristiansen](https://discuss.elastic.co/u/Alex_Kristiansen)\
**Post date:** [September 10, 2019, 10:15pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/4 "2019-09-10T22:15:35Z")

</div>

Alexus,

Can you paste us the config you're using? Has this started with 6.8.2?  
Do you have a way of testing a newer version of Metricbeat to see if you run into the same memory issues?

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 11, 2019, 3:54am UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/5 "2019-09-11T03:54:13Z")

</div>

I use "Beats central management", my config:

`metricbeat.yml`:

```
# grep -v ^# /etc/metricbeat/metricbeat.yml

management:
  enabled: true
  period: 1m0s
  events_reporter:
    period: 30s
    max_batch_size: 1000
  access_token: ${management.accesstoken}
  kibana:
    protocol: https
    host: x.x.x:443
    username: x
    password: x
    ssl: null
    timeout: 10s
    ignoreversion: true
  blacklist:
    output: console|file

# 

```

I just upgraded my beats to 6.8.3:

```
# metricbeat version
metricbeat version 6.8.3 (amd64), libbeat 6.8.3 [9be0dc0ce65850ca0efb7310a87affa193a513a2 built 2019-08-29 18:13:26 +0000 UTC]
#
```

---

<div class="post-metadata">

**Author:** ![Alex\_Kristiansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_kristiansen/32/46086_2.png) [@Alex\_Kristiansen](https://discuss.elastic.co/u/Alex_Kristiansen)\
**Post date:** [September 11, 2019, 3:32pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/6 "2019-09-11T15:32:44Z")

</div>

If you're using CM, what modules and metricsets do you have enabled? Are you still seeing the issue with 6.8.3?

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 11, 2019, 4:07pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/7 "2019-09-11T16:07:50Z")

</div>

modules:

- docker
- rabbitmq
- redis
- system

in about hour since last time I restarted metricbeat.service:

`systemctl status metricbeat.service` output:

```
# systemctl status metricbeat.service 
● metricbeat.service - Metricbeat is a lightweight shipper for metrics.
   Loaded: loaded (/lib/systemd/system/metricbeat.service; enabled; vendor preset: enabled)
   Active: active (running) since Wed 2019-09-11 15:00:15 UTC; 1h 5min ago
     Docs: https://www.elastic.co/products/beats/metricbeat
 Main PID: 8907 (metricbeat)
    Tasks: 30 (limit: 4915)
   Memory: 520.4M
      CPU: 37min 29.201s
   CGroup: /system.slice/metricbeat.service
           └─8907 /usr/share/metricbeat/bin/metricbeat -c /etc/metricbeat/metricbeat.yml -path.home /usr/

Sep 11 15:00:15 app11 systemd[1]: Started Metricbeat is a lightweight shipper for metrics..
# metricbeat version
metricbeat version 6.8.3 (amd64), libbeat 6.8.3 [9be0dc0ce65850ca0efb7310a87affa193a513a2 built 2019-08-29 18:13:26 +0000 UTC]
#
```

---

<div class="post-metadata">

**Author:** ![Alex\_Kristiansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_kristiansen/32/46086_2.png) [@Alex\_Kristiansen](https://discuss.elastic.co/u/Alex_Kristiansen)\
**Post date:** [September 11, 2019, 5:44pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/8 "2019-09-11T17:44:13Z")

</div>

@alexus

Sorry I keep asking for info, it's a bit hard to debug from CM. What output are you using? Are you using the `add_kubernetes_metadata` processor?

Also, can you get a memory profile? You can get one by adding `-httpprof localhost:6060` to metricbeat, and then downloading `http://localhost:6060/debug/pprof/heap`. Wait until you start seeing high memory use, and then download it.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 11, 2019, 8:00pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/9 "2019-09-11T20:00:48Z")

</div>

Please... There is definitely no need to be sorry) I would _love_ to help whichever way I can (help me, help you to help me)

I use `elasticsearch` for output and no I'm not using `add_kubernetes_metadata` (at least for now), how can I transfer heap file over to you?

---

<div class="post-metadata">

**Author:** ![Alex\_Kristiansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_kristiansen/32/46086_2.png) [@Alex\_Kristiansen](https://discuss.elastic.co/u/Alex_Kristiansen)\
**Post date:** [September 11, 2019, 8:25pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/10 "2019-09-11T20:25:13Z")

</div>

@alexus,

It's been a while since I used the memory profiler. If it returns an image, you can just use the image attachment here. If not, maybe you can try a github gist, public s3 bucket or something like that?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2019, 8:25pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085/11 "2019-10-09T20:25:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
