# Some questions of logstash 6

**URL:** <https://discuss.elastic.co/t/some-questions-of-logstash-6/144857>\
**Category:** Logstash\
**Created:** [August 17, 2018, 9:10am UTC](https://discuss.elastic.co/t/some-questions-of-logstash-6/144857 "2018-08-17T09:10:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robin\_Guo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robin_guo/32/42297_2.png) [@Robin\_Guo](https://discuss.elastic.co/u/Robin_Guo)\
**Post date:** [August 17, 2018, 9:10am UTC](https://discuss.elastic.co/t/some-questions-of-logstash-6/144857/1 "2018-08-17T09:10:48Z")

</div>

Dear Elastic,  
I have some questions of Logstash to you.  
Could you please answer my questions?

Best Regards  
Robin

**#####################**  
**logstash server sepc**  
**#####################**

```
Cpu:4 core
Mem: 16g
Java heap: 8g
Logstash version: 6.2.x
NIC:10G

```

**###########################**  
**# logstash pipeline config**  
**###########################**

```
180817162922 root@test101 logstash # cat pipelines.yml |grep -i 'meraki' -A4
- pipeline.id: rsyslog-cisco-meraki
  path.config: /etc/logstash/conf.d/rsyslog-cisco-meraki.conf
  pipeline.batch.size: 2000
  pipeline.workers: 4
  queue.type: persisted
  queue.max_bytes: 1024mb

```

**###########################**  
**# logstash pipeline status**  
**###########################**

```
180817162700 root@test101 logstash # curl -XGET '127.0.0.1:9600/_node/stats/pipelines/rsyslog-cisco-meraki?pretty'

    {
    ..........
    ..........
    ..........

          "queue" : {
            "events" : 0,
            "type" : "persisted",
            "capacity" : {
              "queue_size_in_bytes" : 99431,
              "page_capacity_in_bytes" : 67108864,
              "max_queue_size_in_bytes" : 1073741824,
              "max_unread_events" : 0
            },
            "data" : {
              "path" : "/data/logstash/queue/rsyslog-cisco-meraki",
              "free_space_in_bytes" : 7171907584,
              "storage_type" : "rootfs"
        }
      }
    }

```

**###############**  
**# Questions**  
**###############**

**1. what's the difference between pipeline.batch.size and queue.size ?**

```
1). Is the pipeline.batch.size of pipeline input size, filter size or output size?

2). Is pipeline.batch.size the size to output to Elasticsarch at one time?

```

**2.according to set up above, Are events processed by pipeline like this as below?**

`input-> queue(persisted) ->filer (take out events from queue ) -> output ES(Bulk requests)`

**3. How many events does logstash send to elasticsearch at one time(bulk requests) according to my setup above?**

**4. I found that there few options are removed since logstash 6 for elasticsearch output plugin. if we want to tweak the logsatash output rate to ES for throughput. how can we do that without the below options?**

```
  workers: 1 (by default) before
  flush_size: 500 (by default) before

```

**5. if I change persisted queue back to the memory-based queue, how many events would save in heap by default?**

---

<div class="post-metadata">

**Author:** ![Robin\_Guo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robin_guo/32/42297_2.png) [@Robin\_Guo](https://discuss.elastic.co/u/Robin_Guo)\
**Post date:** [August 20, 2018, 7:44am UTC](https://discuss.elastic.co/t/some-questions-of-logstash-6/144857/2 "2018-08-20T07:44:28Z")

</div>

Hi folks,  
Any feedback?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2018, 7:44am UTC](https://discuss.elastic.co/t/some-questions-of-logstash-6/144857/3 "2018-09-17T07:44:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
