# Persistent Queue Configuration question

**URL:** https://discuss.elastic.co/t/persistent-queue-configuration-question/73408
**Category:** Logstash
**Created:** [January 31, 2017, 6:17pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408 "2017-01-31T18:17:29Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)
#### Post date: [January 31, 2017, 6:17pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/1 "2017-01-31T18:17:29Z")

</div>

Hi,  
This might a very simple question but i am new to logstash.  
I have just configured my logstash instance with the following configuration in the logstash.yml file:

> ```
> path.data: /var/lib/logstash
> queue.type: persisted
> queue.max_bytes: 2gb
> queue.page_capacity: 500mb
> queue.max_events: 0
> 
> ```

Logstash reads data from redis and processes it and sends it to ES cluster.  
When i restart my logstash, i dont see any indication regarding the persistent queue being used or created. There is no 'queue' file created in the path.data directory as mentioned in the docs.  
What am i doing wrong?

Thanks.

---

<div class="post-metadata">

### Author: ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)
#### Post date: [January 31, 2017, 10:28pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/3 "2017-01-31T22:28:02Z")

</div>

Can anyone take a look at this issue please???

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [February 1, 2017, 5:14am UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/4 "2017-02-01T05:14:07Z")

</div>

Please be patient. This forum is manned by volunteers. If you need an SLA associated with you questions Elastic do offer commercial subscriptions that include SLA based support.

The feature you are asking about is also quite new, which means there is a limited number of people who may have practical experience with it and be able to help.

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [February 1, 2017, 10:34am UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/5 "2017-02-01T10:34:36Z")

</div>

Have you read the [docs on configuring persistent queues](https://www.elastic.co/guide/en/logstash/current/persistent-queues.html#configuring-persistent-queues)?

`queue.max_bytes` will be reached first.

In `/var/lib/logstash` you should see a folder `queue` and in that folder there should be a few files, some called `page.<N>`, one called `checkpoint.head` and some called `checkpoint.<N>`.

Events are pushed to the "head" of the queue. Events are pulled from the tail.

If the push rate is equal to the pull rate then one or two pages will be seen on disk. A page that has been read/acknowledged (pulled) is deleted. If the push rate is higher than the pull rate then you will see a number of `page.<N>` files building up.

Questions:

1. Is this a development setup?
2. Is the data in Redis finite?
3. How are you restarting logstash?
4. Are you sure you are editing the `logstash.yml` file that LS is using?

---

<div class="post-metadata">

### Author: ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)
#### Post date: [February 1, 2017, 3:51pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/6 "2017-02-01T15:51:40Z")

</div>

This is a dev environment.  
The data in redis is finite.  
I am restarting logstash with `sudo service logstash restart`  
@guyboertje, I didnt create the folder 'queue' before, but once i created it i am able to see two files: `"checkpoint.head"` and `"page.<N>"`.  
I have configured each page to 500 MB and the `page.<N>` is at 100MB and gradually increasing till 500MB. Does this mean that the data is not being sent over to ES? What does this file contain and when will it be again set to 0MB?  
Thanks

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [February 1, 2017, 5:22pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/7 "2017-02-01T17:22:03Z")

</div>

How much test data are you putting into redis?

Previously, did you see events in ES and was Redis empty?

---

<div class="post-metadata">

### Author: ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)
#### Post date: [February 1, 2017, 5:55pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/8 "2017-02-01T17:55:16Z")

</div>

@guyboertje, I am sorry, the data in redis is not finite. I am feeding live data to the cluster and currently its around 500-1000 events/sec

---

<div class="post-metadata">

### Author: ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)
#### Post date: [February 2, 2017, 7:23pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/9 "2017-02-02T19:23:10Z")

</div>

Hello @guyboertje, I have another query. Is there any way we can confirm the existence of persistence queues?  
Because i tried to get stats on the pipeline by using `curl -XGET 'localhost:9600/_node/stats/pipeline?pretty'` and i see that in the result there is no block showing the stats of persistent queues

> ` "reloads" : { "last_error" : null, "successes" : 0, "last_success_timestamp" : null, "last_failure_timestamp" : null, "failures" : 0 } }`  
> as mentioned [in the docs.](https://www.elastic.co/guide/en/logstash/current/node-stats-api.html#pipeline-stats)  
> Thanks.

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [February 3, 2017, 9:49am UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/10 "2017-02-03T09:49:36Z")

</div>

Metrics for the persistent queue was not shipped in the initial release. It is coming soon.

---

<div class="post-metadata">

### Author: ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)
#### Post date: [February 9, 2017, 9:57pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/11 "2017-02-09T21:57:35Z")

</div>

@guyboertje, I see that whenever the input load increases, multiple checkpoint files are created. When the corresponding page file is processed the checkpoint file needs to be deleted automatically. But my queue folder is filled with multiple files.  
Example:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/149f23acf3cf0de612d9f39fbfbd68fd8f22c340.png)

This is resulting in stalling the logstash shutdown or start process.

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [February 10, 2017, 10:03am UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/12 "2017-02-10T10:03:13Z")

</div>

When the inflow rate of events is higher than the output, as you now know, page and checkpoint files build up.

If a worker thread is slow or very very slow (stuck) it will not have acked its batch so the page and checkpoint that the batch was read from can't be closed and deleted. But other workers will read and ack later pages. In this specific case when a later page is fully acked we only delete the page file and not its checkpoint. This means the PQ has a complete 'breadcrumb' trail from the checkpoint.head back to the unacked page and checkpoint. This allows us to tell on startup if the PQ is corrupted should pages and checkpoints be deleted by some other means.

If the slow worker does eventually loop back and ack its batch then we remove that page and checkpoint and clean the intermediate checkpoint files.

---

<div class="post-metadata">

### Author: ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)
#### Post date: [February 15, 2017, 2:51pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/13 "2017-02-15T14:51:53Z")

</div>

Thanks @guyboertje for the detailed description. But i have been observing the behavior of the queues by creating a small script which gives out the number of events processed by the pipeline. Whenever the persistent queues are enabled, and if there is a sudden spike in the incoming logs (around 1 million in 5 minutes), the pipeline stops processing the events(which is expected according to documentation). But the problem is that when the input events reduce the pipeline is not getting back up to process the events and the logs in redis keep on increasing.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/5/5005cdca78b237dfe1f4685bcdd1b57c7b6160c4.png)  
The above image shows the sudden spike in output events to elasticsearch and after that the pipeline does not start processing the logs from the redis queue.  
I see this behaviour only when persisted queues are enabled.  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/2301545e962feab4a2678c7b2e208dd55c562da5.png)  
Above image is the behaviour when the persistent queues are disabled.

---

<div class="post-metadata">

### Author: ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)
#### Post date: [February 16, 2017, 4:20pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/14 "2017-02-16T16:20:15Z")

</div>

@ash007

This seems to be a bug. Please file a bug report at [https://github.com/elastic/logstash/issues](https://github.com/elastic/logstash/issues)

Make sure you give us extremely detailed instructions of what you did, your versions, configs and sample data.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 16, 2017, 4:20pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408/15 "2017-03-16T16:20:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
