# What is the better way to take full advantage of Logstash (MEM and CPU)?

**URL:** <https://discuss.elastic.co/t/what-is-the-better-way-to-take-full-advantage-of-logstash-mem-and-cpu/43009>\
**Category:** Logstash\
**Created:** [February 29, 2016, 2:51pm UTC](https://discuss.elastic.co/t/what-is-the-better-way-to-take-full-advantage-of-logstash-mem-and-cpu/43009 "2016-02-29T14:51:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![syunusic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syunusic/32/4131_2.png) [@syunusic](https://discuss.elastic.co/u/syunusic)\
**Post date:** [February 29, 2016, 2:51pm UTC](https://discuss.elastic.co/t/what-is-the-better-way-to-take-full-advantage-of-logstash-mem-and-cpu/43009/1 "2016-02-29T14:51:47Z")

</div>

Hi,  
I'm running Logstash 2.2.2 in Ubuntu as a service (sudo service logstash start) and I want to have as much speed (in shipping) as possible. Is it better to run several instances in the same box or using as much memory and RAM as possible in one instance? I'm trying to do the latest... so..  
There is /etc/init.d/logstash. In there, is an option: LS\_HEAP\_SIZE="1g". If I want to make it faster, should I put a bigger number there? My server has 64G in RAM, so I put LS\_HEAP\_SIZE="31g", but the server is using only a little of the RAM.  
Bottom line... what is the best way to make Logstash run as fast as possible?

PS: I also wanted to try the "-w" flag. Is that a good option? Where should I to put it in the /etc/init.d/logstash file? In the "args" section?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 29, 2016, 6:18pm UTC](https://discuss.elastic.co/t/what-is-the-better-way-to-take-full-advantage-of-logstash-mem-and-cpu/43009/2 "2016-02-29T18:18:15Z")

</div>

> In there, is an option: LS\_HEAP\_SIZE="1g". If I want to make it faster, should I put a bigger number there

No, not unless Logstash is running out of heap (which it probably isn't).

> PS: I also wanted to try the "-w" flag. Is that a good option? Where should I to put it in the /etc/init.d/logstash file? In the "args" section?

No, don't touch the init script. Put it in LS\_OPTS in /etc/default/logstash. Logstash 2.2.2 has a pretty reasonable default value though.

But don't make random configuration changes. Where's your performance bottleneck? CPU, disk, something else? What do your inputs look like?

---

<div class="post-metadata">

**Author:** ![syunusic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syunusic/32/4131_2.png) [@syunusic](https://discuss.elastic.co/u/syunusic)\
**Post date:** [March 2, 2016, 4:44pm UTC](https://discuss.elastic.co/t/what-is-the-better-way-to-take-full-advantage-of-logstash-mem-and-cpu/43009/3 "2016-03-02T16:44:26Z")

</div>

I still have RAM, CPU and disk IO available, so I just wanted to use more resources.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:08am UTC](https://discuss.elastic.co/t/what-is-the-better-way-to-take-full-advantage-of-logstash-mem-and-cpu/43009/4 "2017-07-06T05:08:46Z")

</div>


