# When does compression\_level change?

**URL:** <https://discuss.elastic.co/t/when-does-compression-level-change/350659>\
**Category:** Elastic Agent\
**Created:** [January 9, 2024, 1:49pm UTC](https://discuss.elastic.co/t/when-does-compression-level-change/350659 "2024-01-09T13:49:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![slash24](https://avatars.discourse-cdn.com/v4/letter/s/a4c791/32.png) [@slash24](https://discuss.elastic.co/u/slash24)\
**Post date:** [January 9, 2024, 1:49pm UTC](https://discuss.elastic.co/t/when-does-compression-level-change/350659/1 "2024-01-09T13:49:28Z")

</div>

We're on Elastic 8.8.1 and about to upgrade to 8.11.3.  
Since we have alot of issues with Elastic Agents on our Windows-boxes, esp. when endpoint or agent is being reloaded but also with high cpuutilization (mostly due to endpoint/defend), we really dont want any "change" to apply to all agents simultaniously. In the [changelog](https://www.elastic.co/guide/en/fleet/8.11/release-notes-8.11.0.html) for 8.11, it says compression\_level is being set to 0.

we conscider to create a second Output for elastic, setting compression\_level:0 in Advacned YAML, just need to make sure that compression\_level will change when the agents on the servers are being upgraded from 8.5.2 to 8.11.3, and that we safely can upgrade our Fleet-server to 8.11.3 without risk of any changes applying to the agents.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [January 23, 2024, 1:04am UTC](https://discuss.elastic.co/t/when-does-compression-level-change/350659/2 "2024-01-23T01:04:39Z")

</div>

Compression level was available in 8.8 as visible in the docs here: [Configure the Elasticsearch output | Fleet and Elastic Agent Guide [8.8] | Elastic](https://www.elastic.co/guide/en/fleet/8.8/elasticsearch-output.html) as it was available in 8.8 whatever setting you apply will apply to all managed agents. Whether that setting you apply represents a change from the current value will depend on the agent version.

From the release notes:

> The default compression level for Elasticsearch outputs is changing from 0 to 1.

Prior to 8.11 the default was 0 and starting in 8.11.0 the new default is 1.

Please note this does not impact CPU usage for Elastic defend.

It's also worth noting that the 25% CPU increase referenced is for a worst case scenario of Filebeat pulling logs from a file, performing zero processing on them, and then outputting them to elasticsearch.

In the case of winlogbeat, auditbeat and packetbeat the overall CPU impact is significantly lower as those beats spend a lot of CPU time collecting and processing messages and comparatively less CPU time writing them to elasticsearch and so the overall CPU impact from compression is much lower.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2024, 1:04am UTC](https://discuss.elastic.co/t/when-does-compression-level-change/350659/3 "2024-02-20T01:04:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
