# Random number of messages dropping on logstash import

**URL:** <https://discuss.elastic.co/t/random-number-of-messages-dropping-on-logstash-import/251658>\
**Category:** Logstash\
**Created:** [October 10, 2020, 9:13pm UTC](https://discuss.elastic.co/t/random-number-of-messages-dropping-on-logstash-import/251658 "2020-10-10T21:13:58Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![Paul\_Shriner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_shriner/32/76985_2.png) [@Paul\_Shriner](https://discuss.elastic.co/u/Paul_Shriner)\
**Post date:** [October 11, 2020, 1:25am UTC](https://discuss.elastic.co/t/random-number-of-messages-dropping-on-logstash-import/251658/11 "2020-10-11T01:25:00Z")

</div>

How do I discover the LS backlog?

I just found this thread, while older, I have been playing with batch size (100 - 3000 )

> [@Losing messages during high traffic rate](https://discuss.elastic.co/t/losing-messages-during-high-traffic-rate/56449):
>
> I am doing log analysis using Filebeat (1.2) -\> logstash(2.3) -\> Elasticsearch (2.3) I have 4 filebeat instances, 4 logstash instances (6 cores each) , and Elasticsearch cluster (8 cores, 64G RAM) of 2 nodes In Filebeat.yml logstash setting is as such: filebeat: prospectors: - paths: - /var/log/filebeat//.json encoding: utf-8 input\_type: log ignore\_older: 10m scan\_frequency: 1s exclude\_lines: ["^$"] spool\_size: 3072 registry\_file: .filebeat output: logstash: enabled: true hos…

That seems to be a dead end as well.

---

_[View the full topic](https://discuss.elastic.co/t/random-number-of-messages-dropping-on-logstash-import/251658)._
