# What is the best way to profile Logstash?

**URL:** <https://discuss.elastic.co/t/what-is-the-best-way-to-profile-logstash/29956>\
**Category:** Logstash\
**Created:** [September 25, 2015, 2:50am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-profile-logstash/29956 "2015-09-25T02:50:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![thehybridtech](https://avatars.discourse-cdn.com/v4/letter/t/e79b87/32.png) [@thehybridtech](https://discuss.elastic.co/u/thehybridtech)\
**Post date:** [September 25, 2015, 2:50am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-profile-logstash/29956/1 "2015-09-25T02:50:49Z")

</div>

A friend and I wrote a codec to parse syslog data for SAR files. The codec works great but performance is slow. What is the best way to profile logstash? VisualVM or jruby profiler? Is there any documentation on this process?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [September 29, 2015, 8:52am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-profile-logstash/29956/2 "2015-09-29T08:52:06Z")

</div>

There isn't a pain-free way of doing this right now. We're working to have internal performance metrics in Logstash 2.1 or 2.2, with more features being continuously added thereafter.

Using a jruby profiler _works,_ but it slows things down so dramatically that it almost makes it too slow to tell what's really slowing things down.

---

<div class="post-metadata">

**Author:** ![andrewvc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewvc/32/5064_2.png) [@andrewvc](https://discuss.elastic.co/u/andrewvc)\
**Post date:** [September 29, 2015, 10:09am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-profile-logstash/29956/3 "2015-09-29T10:09:12Z")

</div>

You can always to removing bits and pieces of the pipeline and comparing before and after.

If it's definitely in the codec, then that's more of a jruby question. I'd personally start with a reading of the codec code and just looking for any low-hanging fruit.

---

<div class="post-metadata">

**Author:** ![thehybridtech](https://avatars.discourse-cdn.com/v4/letter/t/e79b87/32.png) [@thehybridtech](https://discuss.elastic.co/u/thehybridtech)\
**Post date:** [September 29, 2015, 3:16pm UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-profile-logstash/29956/4 "2015-09-29T15:16:36Z")

</div>

Thank you for the feedback. I look forward to to the internal performance metrics.

---

<div class="post-metadata">

**Author:** ![otisg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/otisg/32/492_2.png) [@otisg](https://discuss.elastic.co/u/otisg)\
**Post date:** [September 30, 2015, 2:36pm UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-profile-logstash/29956/5 "2015-09-30T14:36:04Z")

</div>

Hi,

You could use SPM today just to get an idea of various JVM metrics for the JVM that runs your Logstash. We've done that here a long time ago: [http://blog.sematext.com/2013/11/05/logstash-performance-monitoring/](http://blog.sematext.com/2013/11/05/logstash-performance-monitoring/)

You'll also get OS metrics, too, which may be relevant here as well. Once Logstash starts exposing metrics you'll see its logo on [http://sematext.com/spm/integrations](http://sematext.com/spm/integrations) . Looking forward to that!

Otis

---

<div class="post-metadata">

**Author:** ![simmel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simmel/32/48040_2.png) [@simmel](https://discuss.elastic.co/u/simmel)\
**Post date:** [October 1, 2015, 2:10pm UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-profile-logstash/29956/6 "2015-10-01T14:10:01Z")

</div>

Or any of the F/OSS alternatives.

We use [https://github.com/jmxtrans/jmxtrans-agent/](https://github.com/jmxtrans/jmxtrans-agent/) combined with  
Graphite and are very pleased with the results.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:27am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-profile-logstash/29956/7 "2017-07-06T05:27:32Z")

</div>


