# Why am I getting such poor performance?

**URL:** <https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567>\
**Category:** Logstash\
**Created:** [November 6, 2018, 3:12pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567 "2018-11-06T15:12:55Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![monk](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@monk](https://discuss.elastic.co/u/monk)\
**Post date:** [November 6, 2018, 3:12pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/1 "2018-11-06T15:12:55Z")

</div>

I've got a large (23M record) CSV file I want to upload once to ES. I've made a few small tweaks to my LS config (10 workers, batch size 5000, Xms and Xmx 5 Gb), but it still uploads only about 1000 records/s, compared to the Python ES bulk upload, which achieves 10k/sec (with a single process, and I assume, thread). Is there an obvious setting I'm missing?

I'd rather not have to write or maintain any code myself, but unless there's a quick and simple way to improve LS performance, maybe it's the better route? It will only be used for occasional one-off batch uploads.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 6, 2018, 4:26pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/2 "2018-11-06T16:26:12Z")

</div>

What does your config look like? Which filters are you using?

---

<div class="post-metadata">

**Author:** ![monk](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@monk](https://discuss.elastic.co/u/monk)\
**Post date:** [November 6, 2018, 4:29pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/3 "2018-11-06T16:29:10Z")

</div>

Just the CSV filter, given the separator and columns. Everything else in the config looks standard (a single input file, and ES output). Should I paste anything in particular?

---

<div class="post-metadata">

**Author:** ![monk](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@monk](https://discuss.elastic.co/u/monk)\
**Post date:** [November 7, 2018, 5:44pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/4 "2018-11-07T17:44:29Z")

</div>

As I write the Python code to use multiprocessing and deal with error scenarios, I'm increasingly hoping I will be able to rely on Logstash, if only I can configure it easily to perform at a similar speed.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 7, 2018, 5:48pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/5 "2018-11-07T17:48:43Z")

</div>

That sounds slow. How large are your events? How many columns? Is your python script running on the same hardware? What is the specification of the machine Logstash is running on?

---

<div class="post-metadata">

**Author:** ![monk](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@monk](https://discuss.elastic.co/u/monk)\
**Post date:** [November 7, 2018, 6:03pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/6 "2018-11-07T18:03:21Z")

</div>

The events are small. There are 11 columns, 10 of which are strings (250ish chars total) and one of which is an ip\_range. The python script is running on the same machine as ES (as is Logstash). I've tried across three machines: a 2016 Macbook Pro and two cloud virtual machines (with 1 CPU/15GB ram and 16 CPU/240 GB ram respectively). In all cases, LS gets ~1k qps. Python bulk gets between 10k-20k.

Part of the problem might be the default logging (and the overhead of sending the console output over ssh to my machine so I can watch it and conduct my simplistic timing), but that seems unlikely to account for all of the difference.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 7, 2018, 6:06pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/7 "2018-11-07T18:06:23Z")

</div>

I have seen reports that the dissect filter might be faster than the csv filter. Might be worth trying it to see if it makes any difference.

---

<div class="post-metadata">

**Author:** ![monk](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@monk](https://discuss.elastic.co/u/monk)\
**Post date:** [November 7, 2018, 6:08pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/8 "2018-11-07T18:08:36Z")

</div>

Ah yes thanks, just noticed [https://github.com/logstash-plugins/logstash-filter-csv/issues/46](https://github.com/logstash-plugins/logstash-filter-csv/issues/46). I'll try that out.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 7, 2018, 6:09pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/9 "2018-11-07T18:09:56Z")

</div>

It may also be worthwhile trying with a smaller batch size. Bigger is not always better and can add pressure to your cluster.

---

<div class="post-metadata">

**Author:** ![monk](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@monk](https://discuss.elastic.co/u/monk)\
**Post date:** [November 7, 2018, 11:35pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/10 "2018-11-07T23:35:48Z")

</div>

The dissect filter was very slightly faster, and reducing batch size (to 500) slightly more still. But it's still ~10x slower than using Python. If anyone on your team has any further ideas, that'd be swell. Otherwise, onward with Python!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 8, 2018, 2:56am UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/11 "2018-11-08T02:56:00Z")

</div>

I am surprised the difference is so big. It would probably help if you could share you config and how you are running Logstash.

---

<div class="post-metadata">

**Author:** ![monk](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@monk](https://discuss.elastic.co/u/monk)\
**Post date:** [November 8, 2018, 4:05pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/12 "2018-11-08T16:05:34Z")

</div>

Sure. The config is simple. This is with the CSV filter; the dissect version is basically the same:

```
input {
  file {
    path => "/tmp/2018-10-28-pfxs3.txt"
    start_position => "beginning"
    sincedb_path => "/dev/null"
  }
}
filter {
  csv {
    separator => "	"
    columns => ["key_prefix", "match_prefix", "string_feature1, "string_feature2", "string_feature3", "string_feature4", "string_feature5", "string_feature6", "numeric_feature1", "string_feature7", "string_feature8"]
  }
}
output {
   elasticsearch {
     hosts => "http://localhost:9200"
     index => "prefix"
     template => "prefix-template.json"
     template_overwrite => true     
  }
stdout {}
}

```

I just run `logstash -f prefixes.conf`. The `logstash.yml` is basically the default. And `prefix-template.json` just makes `key_prefix` an `ip_range`. Anything else it would be useful to know?

---

<div class="post-metadata">

**Author:** ![monk](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@monk](https://discuss.elastic.co/u/monk)\
**Post date:** [November 20, 2018, 4:35pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/13 "2018-11-20T16:35:23Z")

</div>

Any thoughts?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 20, 2018, 4:39pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/14 "2018-11-20T16:39:30Z")

</div>

No, I do not see anything that stands out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2018, 4:39pm UTC](https://discuss.elastic.co/t/why-am-i-getting-such-poor-performance/155567/15 "2018-12-18T16:39:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
