# Slow Ingestion of Final Log Chunks (Filebeat + Logstash + Elasticsearch)

**URL:** <https://discuss.elastic.co/t/slow-ingestion-of-final-log-chunks-filebeat-logstash-elasticsearch/377214>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [April 16, 2025, 5:14pm UTC](https://discuss.elastic.co/t/slow-ingestion-of-final-log-chunks-filebeat-logstash-elasticsearch/377214 "2025-04-16T17:14:10Z")\
**Posts on this page:** 3\
**Page:** 2

<div class="post-metadata">

**Author:** ![RafaelXokito](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafaelxokito/32/142668_2.png) [@RafaelXokito](https://discuss.elastic.co/u/RafaelXokito)\
**Post date:** [April 24, 2025, 3:50pm UTC](https://discuss.elastic.co/t/slow-ingestion-of-final-log-chunks-filebeat-logstash-elasticsearch/377214/21 "2025-04-24T15:50:08Z")

</div>

Results after replacing action "update" with action "create":

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/b/ebd93e233985821a21881e72b094da6c7cdc8abc.png)

Without any duplicated event, this was the result:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fb7c58f46f2ac8bb235a2234b9345f8a7b2b2454.png)

Since I found the solution, I will close this thread.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 24, 2025, 4:37pm UTC](https://discuss.elastic.co/t/slow-ingestion-of-final-log-chunks-filebeat-logstash-elasticsearch/377214/22 "2025-04-24T16:37:20Z")

</div>

Did you tested with memory queue at any point?

---

<div class="post-metadata">

**Author:** ![RafaelXokito](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafaelxokito/32/142668_2.png) [@RafaelXokito](https://discuss.elastic.co/u/RafaelXokito)\
**Post date:** [May 7, 2025, 1:08pm UTC](https://discuss.elastic.co/t/slow-ingestion-of-final-log-chunks-filebeat-logstash-elasticsearch/377214/23 "2025-05-07T13:08:54Z")

</div>

> [@leandrojmp](#):
>
> Did you tested with memory queue at any point?

Yes, as I mentioned here I changed filebeat disk queue to memory, and every test made after that included that change.

> [@RafaelXokito](#):
>
> Filebeat queue storage from disk to memory

[Previous page](https://discuss.elastic.co/t/slow-ingestion-of-final-log-chunks-filebeat-logstash-elasticsearch/377214.md?page=1)
