# Specifying Logstash filter workers?

**URL:** <https://discuss.elastic.co/t/specifying-logstash-filter-workers/236089>\
**Category:** Logstash\
**Created:** [June 7, 2020, 2:15pm UTC](https://discuss.elastic.co/t/specifying-logstash-filter-workers/236089 "2020-06-07T14:15:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mskadu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mskadu/32/69520_2.png) [@mskadu](https://discuss.elastic.co/u/mskadu)\
**Post date:** [June 7, 2020, 2:15pm UTC](https://discuss.elastic.co/t/specifying-logstash-filter-workers/236089/1 "2020-06-07T14:15:23Z")

</div>

I am currently trialling the use of the Aggregated Filter plugin within Logstash v7.7 for a specific use case. I noticed that the description the specific Plugin ([here](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate-description)) says:

> You should be very careful to set Logstash filter workers  
> to 1 ( `-w 1` flag) for this filter to work correctly otherwise  
> events may be processed out of sequence and unexpected  
> results will occur.

I have already looked through everything under /etc/logstash and could not find anywhere where this could be specified? The closest I got was pipeline.workers in /etc/logstash/logstash.yml which is accompanied by the comment

> Set the number of workers that will, in parallel, execute the filters+outputs stage of pipelines.
> 
> This defaults to the number of hosts's CPU cores.

Don't suppose this is it?

PS: I have already looked through [this fairly dated thread](https://discuss.elastic.co/t/how-to-specify-number-of-logstash-workers-in-configuration-file/32972).

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 7, 2020, 4:33pm UTC](https://discuss.elastic.co/t/specifying-logstash-filter-workers/236089/2 "2020-06-07T16:33:59Z")

</div>

You can set it in logstash.yml. You can set it per-pipeline in pipelines.yml, or you can set it on the command line using -w 1

In 7.7 you will also need to [disable java execution](https://github.com/elastic/logstash/issues/10938) to preserve the order of events.

---

<div class="post-metadata">

**Author:** ![mskadu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mskadu/32/69520_2.png) [@mskadu](https://discuss.elastic.co/u/mskadu)\
**Post date:** [June 7, 2020, 4:47pm UTC](https://discuss.elastic.co/t/specifying-logstash-filter-workers/236089/3 "2020-06-07T16:47:37Z")

</div>

Thanks! Could you please point me to the docs/ link that specifies which config to set?

> [@Badger](#):
>
> You can set it in logstash.yml. You can set it per-pipeline in pipelines.yml, or you can set it on the command line using -w 1

Also, TA for the disable java execution pointer 🖖

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 7, 2020, 5:12pm UTC](https://discuss.elastic.co/t/specifying-logstash-filter-workers/236089/4 "2020-06-07T17:12:09Z")

</div>

Docs for the [command line](https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html), [logstash.yml](https://www.elastic.co/guide/en/logstash/current/logstash-settings-file.html), and [pipelines.yml](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html).

---

<div class="post-metadata">

**Author:** ![mskadu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mskadu/32/69520_2.png) [@mskadu](https://discuss.elastic.co/u/mskadu)\
**Post date:** [June 7, 2020, 6:20pm UTC](https://discuss.elastic.co/t/specifying-logstash-filter-workers/236089/5 "2020-06-07T18:20:29Z")

</div>

Ah, thanks! 🙂

The command line docs confirmed that `-w` is the same as `pipeline.workers`. And it can be set in both, logstash.yml and pipelines.yml (per-pipeline).

And also, that disabling java execution can be done by setting:

```auto
pipeline.java_execution: false # default true

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2020, 6:20pm UTC](https://discuss.elastic.co/t/specifying-logstash-filter-workers/236089/6 "2020-07-05T18:20:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
