# Thread consumption in Filebeats

**URL:** <https://discuss.elastic.co/t/thread-consumption-in-filebeats/87313>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 27, 2017, 1:00am UTC](https://discuss.elastic.co/t/thread-consumption-in-filebeats/87313 "2017-05-27T01:00:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![filebeater](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/filebeater/32/18565_2.png) [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Post date:** [May 27, 2017, 1:00am UTC](https://discuss.elastic.co/t/thread-consumption-in-filebeats/87313/1 "2017-05-27T01:00:21Z")

</div>

Hello, I have a question on Filebeat internal:  
From reading Filebeat documentation "[https://www.elastic.co/guide/en/beats/filebeat/current/how-filebeat-works.html](https://www.elastic.co/guide/en/beats/filebeat/current/how-filebeat-works.html)",  
One harvester is started for each file. I am wondering Does each harvester has its own thread?  
For example, if I have 20-30 log files to watch for concurrently, FileBeat will start 20-30 threads for this?

Thanks!  
yan

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 29, 2017, 7:52am UTC](https://discuss.elastic.co/t/thread-consumption-in-filebeats/87313/2 "2017-05-29T07:52:34Z")

</div>

The Go runtime works a bit differently. Each harvester is a goroutine. These goroutines get scheduled on a pool of OS threads. The number of OS threads for the whole of Filebeat can be controlled from the [`GOMAXPROCS` env variable](https://golang.org/pkg/runtime/) and it defaults to the number of CPU cores on the machine.

---

<div class="post-metadata">

**Author:** ![filebeater](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/filebeater/32/18565_2.png) [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Post date:** [May 30, 2017, 8:47pm UTC](https://discuss.elastic.co/t/thread-consumption-in-filebeats/87313/3 "2017-05-30T20:47:16Z")

</div>

@tudor, thanks for the pointer!  
would the performance of filebeat be compromised if I set GOMAXPROCS to 1? or can I set GOMAXPROCS to be 1, expecting reasonable performance? We are fine with some log processing lag as long as it is less than, say, 1 minute.

I am wondering what is the rationale of setting its default to the number of CPU cores on the machine?  
Filebeat is supposed to be deployed on edge machines where the actual service is running. I would want to and minimize the Filebeat overhead and save the maximum CPU power to my service, which requires CPU and memory bandwidth.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 31, 2017, 8:46am UTC](https://discuss.elastic.co/t/thread-consumption-in-filebeats/87313/4 "2017-05-31T08:46:38Z")

</div>

What we usually recommend is setting the `nice` value to 19 for the Filebeat process, so it will read the log files as fast as there are free resources, while still giving way to the more application services. Generally giving it 1 core should be plenty, but you never know when an application starts writing tens of thousands of log lines per second and you don't want to lag. It's perfectly fine to limit it to one core, if you prefer, or you can use cgroup limits to restrict it even more.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2017, 8:46am UTC](https://discuss.elastic.co/t/thread-consumption-in-filebeats/87313/5 "2017-06-28T08:46:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
