# Metricbeat, Filebeat spawning lots of child procs

**URL:** <https://discuss.elastic.co/t/metricbeat-filebeat-spawning-lots-of-child-procs/300503>\
**Category:** Beats\
**Tags:** filebeat, metricbeat\
**Created:** [March 23, 2022, 8:30pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat-spawning-lots-of-child-procs/300503 "2022-03-23T20:30:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![perfecto25](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/perfecto25/32/38070_2.png) [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Post date:** [March 23, 2022, 8:30pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat-spawning-lots-of-child-procs/300503/1 "2022-03-23T20:30:49Z")

</div>

Hello, Im running fbeat, mbeat 7.17 on centos 7

I see it spawning off tons of child procs, is there way to limit this? Whats the reason why so many procs are spawned?

 ![ksnip_20220323-163037](https://us1.discourse-cdn.com/elastic/original/3X/5/3/5353a0ca916bf277259a1b7755326ce84b588d6f.png)

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [March 24, 2022, 2:14pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat-spawning-lots-of-child-procs/300503/2 "2022-03-24T14:14:46Z")

</div>

Could you please share your config file? How do you start the application?

---

<div class="post-metadata">

**Author:** ![perfecto25](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/perfecto25/32/38070_2.png) [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Post date:** [March 25, 2022, 3:31pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat-spawning-lots-of-child-procs/300503/3 "2022-03-25T15:31:29Z")

</div>

standard systemd start up script (comes w rpm install)

config

```auto
filebeat.inputs:
#============================= Filebeat modules ===============================

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: false

  # Period on which files under path should be checked for changes
  #reload.period: 10s

filebeat.modules:
- module: system
  enabled: True
- module: iptables
  enabled: True

#==================== Elasticsearch template setting ==========================

setup.template.settings:
  index.number_of_shards: 1
  setup.template.enabled: true
  setup.template.overwrite: true

#============================== Kibana =====================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.
# This requires a Kibana endpoint configuration.
setup.kibana:

  # Kibana Host
  # Scheme and port can be left out and will be set to the default (http and 5601)
  # In case you specify and additional path, the scheme is required: http://localhost:5601/path
  # IPv6 addresses should always be defined as: https://[2001:db8::1]:5601
  host: "https://xxxx.com:5601"
  username: "beats_setup"
  password: "xxxxx"
  ssl:
    certificate_authorities: "/etc/pki/elastic/ca.crt"
    verification_mode: "certificate"
  # Kibana Space ID
  # ID of the Kibana Space into which the dashboards should be loaded. By default,
  # the Default Space will be used.
  #space.id:
#================================ Outputs =====================================

# Configure what output to use when sending the data collected by the beat.

#-------------------------- Elasticsearch output ------------------------------
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["https://xxxxx.com:9200"]

  # Optional protocol and basic auth credentials.
  protocol: "https"
  #api_key: "Zkl1MmdYMEJlUlR6VkVmb09YVmg6Rk9ITExlR1BTTVNXNjNQX3JuY2h0dw=="
  username: "beats_writer"
  password: "xxxxxx"
  ssl:
    certificate_authorities: ["/etc/pki/elastic/ca.crt"]
    verification_mode: "certificate"
#================================ Processors =====================================

# Configure processors to enhance or manipulate events generated by the beat.

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~

#================================ Logging =====================================

# Sets log level. The default log level is info.
# Available log levels are: error, warning, info, debug
logging.level: error

```

with pstree and htop, I do see tons of sleeping child procs

is there a reason so many child procs are being spawned and then remain in S state? Is it because of lingering tcp connections?

 ![ksnip_20220325-113042](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a59e5e15e4f138084be4bc327934981a8f03333f.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2022, 5:31pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat-spawning-lots-of-child-procs/300503/4 "2022-04-22T17:31:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
