# Out of memory error with logstash 7.6.2

**URL:** <https://discuss.elastic.co/t/out-of-memory-error-with-logstash-7-6-2/227286>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring, docker\
**Created:** [April 9, 2020, 9:17am UTC](https://discuss.elastic.co/t/out-of-memory-error-with-logstash-7-6-2/227286 "2020-04-09T09:17:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sevy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sevy/32/65931_2.png) [@Sevy](https://discuss.elastic.co/u/Sevy)\
**Post date:** [April 9, 2020, 9:17am UTC](https://discuss.elastic.co/t/out-of-memory-error-with-logstash-7-6-2/227286/1 "2020-04-09T09:17:29Z")

</div>

Hi everyone,  
I have a **Logstash 7.6.2 docker** that stops running because of memory leak. After each pipeline execution, it looks like Logstash doesn't release memory.  
**What should I do to identify the source of the problem?**  
**How can I solve it?**

Here is the error I see in the logs. These are just the 5 first lines of the Traceback. I uploaded the rest in a file in my github [there](https://github.com/yviouswilliamous/Logstash-error/blob/master/logstash_traceback.txt).

```auto
 logstash | [2020-04-08T18:15:42,960][INFO][logstash.outputs.file][rawweb] Closing file /output/web_data.json
 logstash | [2020-04-08T18:15:43,353][ERROR][org.logstash.Logstash] java.lang.OutOfMemoryError: Java heap space
 logstash | [2020-04-08T18:15:43,367][ERROR][org.logstash.execution.WorkerLoop][rawclient] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash.
 logstash | org.jruby.exceptions.NoMethodError: (NoMethodError) undefined method `pop' for nil:NilClass
 logstash | at usr.share.logstash.vendor.bundle.jruby.$2_dot_5_dot_0.gems.awesome_print_minus_1_dot_7_dot_0.lib.awesome_print.inspector.awesome(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/awesome_print-1.7.0/lib/awesome_print/inspector.rb:117) ~[?:?]

```

Here the docker-compose.yml I used to configure my Logstash Docker

```
version: '2.4'    
services:
      logstash:
        image: docker.elastic.co/logstash/logstash:7.6.2
        container_name: logstash
        environment:
          LS_JAVA_OPTS: "-Xmx7g -Xms4g"
          REQUEST_FREQUENCY: 600 #seconds
        volumes:
          - ./logstash/config/logstash.yml:/usr/share/logstash/config/logstash.yml:ro
          - ./logstash/pipelines.yml:/usr/share/logstash/config/pipelines.yml
          - ./logstash/pipeline:/usr/share/logstash/pipeline:ro
          - ./logstash/tests:/testscripts:ro
          - /root/logstash_output/:/output/
        ports:
          - "9600:9600"
        mem_limit: 7000M
        mem_reservation: 100M

```

My **pipelines.yml** file

```auto
- pipeline.id: rawclient
  path.config: "/usr/share/logstash/pipeline/logclient.conf"
  pipeline.batch.size: 10000000

 - pipeline.id: rawweb
   path.config: "/usr/share/logstash/pipeline/logweb.conf"
   pipeline.batch.size: 10000000

```

One of my .conf files. Basically, it executes a **.sh** script containing a curl request. The resulte of this request is the input of the pipeline. Treatments are made. Then results are stored in file. The two pipelines do the same, the only difference is the curl request that is made.

```auto
input {
  exec {
    command => "bash /testscripts/logclient_1.sh"
    codec => "json"
    interval => "600"
  }
}

filter {
    mutate {
        rename => ["connection/start_time", "start_time"]
        rename => ["connection/end_time", "end_time"]
        rename => ["connection/duration", "duration"]
        rename => ["connection/destination_ip_address", "destination_ip_address"]
        rename => ["connection/status", "status"]
        rename => ["device/last_ip_address", "last_ip_address"]
        rename => ["user/sid", "sid"]
        # rename => ["binary/application_category", "application_category"]
        rename => ["binary/application_name", "application_name"]
        rename => ["binary/executable_name", "executable_name"]
        remove_field => ["@timestamp"]
        remove_field => ["@version"]
        add_field => { "connection_type" => "client" }
    }
}
output {
  file {
   path => "/output/client_data.json"
   codec => "json"
 }
  stdout {
   codec => rubydebug
 }
}

```

My **logstash.yml** file

```auto
http.host: "0.0.0.0"
xpack.monitoring.enabled: false

```

Thanks for all the help 🙂

---

<div class="post-metadata">

**Author:** ![Sevy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sevy/32/65931_2.png) [@Sevy](https://discuss.elastic.co/u/Sevy)\
**Post date:** [April 9, 2020, 3:31pm UTC](https://discuss.elastic.co/t/out-of-memory-error-with-logstash-7-6-2/227286/2 "2020-04-09T15:31:54Z")

</div>

I also posted my problem on stack overflow [here](https://stackoverflow.com/questions/61119933/uncomprehensible-out-of-memory-error-with-logstash/61120169#61120169) and I got a solution.

The problem came from the high value of batch size. That was two much data loaded in memory before executing the treatments. It caused heap overwhelming.

So I reduced batch size

That's it ^^

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2020, 3:31pm UTC](https://discuss.elastic.co/t/out-of-memory-error-with-logstash-7-6-2/227286/3 "2020-05-07T15:31:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
