# Performance Issues with Logstash UDP/IPFIX

**URL:** <https://discuss.elastic.co/t/performance-issues-with-logstash-udp-ipfix/75069>\
**Category:** Logstash\
**Created:** [February 14, 2017, 3:33pm UTC](https://discuss.elastic.co/t/performance-issues-with-logstash-udp-ipfix/75069 "2017-02-14T15:33:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![beshbesh](https://avatars.discourse-cdn.com/v4/letter/b/f05b48/32.png) [@beshbesh](https://discuss.elastic.co/u/beshbesh)\
**Post date:** [February 14, 2017, 3:33pm UTC](https://discuss.elastic.co/t/performance-issues-with-logstash-udp-ipfix/75069/1 "2017-02-14T15:33:22Z")

</div>

Hello,

I have been trying to get Logstash to be able to process as many IPFIX (Netflow v10) packets as possible. I have seen some cases where Logstash users easily reached 40k events per second, or even up to 90k:

> [@UDP/TCP performance test, UDP drops messages](https://discuss.elastic.co/t/udp-tcp-performance-test-udp-drops-messages/2037):
>
> I was doing perf test to Logstash's network inputs, UDP/TCP. I wrote a python script to simulate some messages generator from network. The python script and Logstash is located in different machines in LAN. So the setup looks like this: python socket-\>tcp/udp-\>logstash-\>local file After some rough tests, I observed that at least in my method of testing, UDP drops lots of messages and TCP works fine with an acceptable performance (10 clients each send 100k msg in 37s). My testing python script…

> [@UDP/Netflow Performance](https://discuss.elastic.co/t/udp-netflow-performance/2737):
>
> Hi there, Can anyone share experience about server scaling and UDP performance. my Logstash setup is quite simple: UDP input with Netflow Codec -\> no Filters -\> Elasticsearch output via HTTP via bulk API My current test environment is based on a quite outdated 4Core Xeon (E5320) with 16GB RAM and 10k SAS drives in Raid1 configuration. I'm collecting about 2k flows per second from one of our edge routers which causes an average system load of 4.0 during daily peaks. Nearly all of the CPU lo…

I have tried many combinations of the settings: flush\_size, workers (input workers), queue\_size, options in logstash.yml and sysctl.conf parameters. My current Logstash configuration is as following, where I can process approximately 5k events per second.

```auto
input
{
        udp
        {
                port => 9995
                codec => netflow
                {
                        versions => [10]
                        target => ipfix
                }
                type => "ipfix"
                queue_size => 15000
                workers => 4
        }
}
filter
{
        metrics
        {
                meter => "events"
                add_tag => "metric"
        }
}
output
{
        if "metric" in [tags]
        {
                file
                {
                        path => "/var/log/logstash/metrics.log"
                        codec => line
                        {
                                format => "rate: %{[events][rate_1m]}"
                        }
                }
        }

        elasticsearch
        {
                hosts => [ "host1:9200"
                                , "host2:9200"
                                , "host3:9200" ]
                index => "ipfix-%{+YYYY.MM.dd}"
                flush_size => 500
        }
}

```

I run Logstash instances on VMWare ESX machines, as virtual machines with Ubuntu server 16.10, 8 cores each and 8 GB RAM. The Logstash heap size is set to min: 2gb and max: 4gb. The virtual machines are connected by 10GBit/s fiber and VMXNET3.

When I increase the number of flows per second I start to notice packet drops:

```auto
root@logstash:/var/log/logstash# netstat -su | grep errors
    85729629 packet receive errors

```

I did a lot of searching and tuning in kernel parameters and ethtool commands, but I cannot get around them. I have tried many things over a long time. What can I possibly be doing wrong?

Thanks a lot in advance!  
-Gijs

---

<div class="post-metadata">

**Author:** ![beshbesh](https://avatars.discourse-cdn.com/v4/letter/b/f05b48/32.png) [@beshbesh](https://discuss.elastic.co/u/beshbesh)\
**Post date:** [February 21, 2017, 1:04pm UTC](https://discuss.elastic.co/t/performance-issues-with-logstash-udp-ipfix/75069/2 "2017-02-21T13:04:33Z")

</div>

I have tried the generator input to find out how many events Logstash can theoretically process, and the output was as following (metrics.log, tested on a 6-core machine):

```auto
...
rate: 67697.47787382574
rate: 67765.33794824105
rate: 67852.94224895787
rate: 67931.44726019318
rate: 67968.97463324976
rate: 68013.52791363167
...

```

Whereas with the same machine with the UDP input and Netflow codec does not go any further than:

```auto
...
rate: 4053.6175391807656
rate: 4057.2621115182033
rate: 4071.53721290261
rate: 4074.2447318672644
rate: 4074.640933231486
rate: 4081.098071688952
...

```

Is the Netflow plugin (logstash-codec-netflow) designed for a high number of flows per second? I have to be able to parse at least 40k flow per second, probably a few multiples of that. I have doubts about whether the Netflow codec is the right way to go. If not, I need to find another way!

Thanks,  
-Gijs

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2017, 1:05pm UTC](https://discuss.elastic.co/t/performance-issues-with-logstash-udp-ipfix/75069/3 "2017-03-21T13:05:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
