# Stability Issues at 10k EPS in Elastic-Agent + Logstash – Elasticsearch Bottleneck?

**URL:** <https://discuss.elastic.co/t/stability-issues-at-10k-eps-in-elastic-agent-logstash-elasticsearch-bottleneck/368960>\
**Category:** Logstash\
**Created:** [October 17, 2024, 3:31am UTC](https://discuss.elastic.co/t/stability-issues-at-10k-eps-in-elastic-agent-logstash-elasticsearch-bottleneck/368960 "2024-10-17T03:31:49Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![wangsubo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wangsubo/32/133865_2.png) [@wangsubo](https://discuss.elastic.co/u/wangsubo)\
**Post date:** [October 17, 2024, 3:31am UTC](https://discuss.elastic.co/t/stability-issues-at-10k-eps-in-elastic-agent-logstash-elasticsearch-bottleneck/368960/1 "2024-10-17T03:31:49Z")

</div>

1. 

I am currently using Elastic-Agent for log collection and Logstash for log forwarding. I am conducting a stress test to evaluate the hardware requirements and costs of the collector setup (Elastic-Agent + Logstash). I have set the Logstash batch size to 1000.

Apache JMeter (192.168.3.170) -\> Elastic-Agent [Fortigate] (192.168.3.172:515) -\> Logstash (192.168.3.172:5044) -\> Elasticsearch (8 Core/16 GB RAM/512 GB SSD)

```auto
input {
  elastic_agent {
    port => 5044
    ssl_enabled => true
    ssl_certificate_authorities => ["/etc/logstash/certs/elasticsearch-ca.pem"]
    ssl_certificate => "/etc/logstash/certs/logstash.crt"
    ssl_key => "/etc/logstash/certs/logstash.pkcs8.key"
    ssl_client_authentication => "required"
  }
}

filter {
  grok {
    match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{IP:syslog_ip} %{GREEDYDATA:message}" }
    overwrite => ["message"]
  }

  
  mutate {
    remove_field => ["syslog_timestamp", "syslog_ip"]
  }

  
  if [message] =~ /type="utm" subtype="ips"/ or [message] =~ /type="event" subtype="system"/ {
    mutate {
      add_tag => ["send_to_QRadar"]
    }
  } else {
    mutate {
      add_tag => ["send_to_elasticsearch"]
    }
  }
}

output {

  
  if "send_to_QRadar" in [tags] {
    tcp {
      host => "192.168.3.180"
      port => 514
      codec => line {
        format => "%{message}"
      }
    }
  }
  if "send_to_elasticsearch" in [tags] {
    elasticsearch {
      hosts => ["https://192.168.3.171:9200"]
      data_stream => "true"
      user => "elastic"
      password => "password"
      cacert => "/etc/logstash/certs/elasticsearch-ca.pem"
    }
  }
}

```

At 10,000 EPS during the stress test, using the configuration above, the Logstash monitoring curve becomes unstable, holding at approximately 6,000-7,000 EPS.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a853a15ab3af47a42597deac63d0a6440ae701d.png)

I suspect the issue might be with Elasticsearch. However, after reviewing the monitoring data, there’s no sign of excessive CPU or RAM usage on Elasticsearch. I also checked the I/O statistics using iostat, and it doesn’t seem to be an I/O issue either.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/0/3059e0a91cce4a9a0aa7c182919bffe2fcaf6df8.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/7/1727bdf546d40fdb2174b180c4bd6ee63ca8e0c1.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/8/1829a76336965b91eb0704fb76895b993b33227d.png)

1. 

When I change the output to null, the Logstash monitoring curve stabilizes at around 10,000 EPS.  
Apache JMeter (192.168.3.170) -\> Elastic-Agent [Fortigate] (192.168.3.172:515) -\> Logstash (192.168.3.172:5044) -\> Output Null

```auto
output {
  null {}
}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/2/52a2420937c662a65f019df3209d1f8171105b36.png)

Does anyone have insights into what could be causing this problem?
