# Window size never grow up

**URL:** <https://discuss.elastic.co/t/window-size-never-grow-up/169517>\
**Category:** Beats\
**Created:** [February 22, 2019, 5:33am UTC](https://discuss.elastic.co/t/window-size-never-grow-up/169517 "2019-02-22T05:33:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![keyolk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keyolk/32/23955_2.png) [@keyolk](https://discuss.elastic.co/u/keyolk)\
**Post date:** [February 22, 2019, 5:33am UTC](https://discuss.elastic.co/t/window-size-never-grow-up/169517/1 "2019-02-22T05:33:33Z")

</div>

In our service environment,  
some of filebeats consume almost 100% of cpu core.

After checking lumberjack protocol [link](https://github.com/logstash-plugins/logstash-input-beats/blob/v2.0.0/PROTOCOL.md) and its tcpdump,  
I found that it always sends window size 1

And from below seems that if windowSize become same to maxOkSize, ( ex, both are 1 )  
it is never been changed.

> <https://github.com/elastic/beats/blob/master/libbeat/outputs/logstash/window.go#L51>

Is It will be mitigated by setting TTL? to reset window size to 10

Or is there a plan to implement commented line from the source ? which below

> // TODO: use duration until ACK to estimate an ok max window size value

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [February 22, 2019, 8:45am UTC](https://discuss.elastic.co/t/window-size-never-grow-up/169517/2 "2019-02-22T08:45:01Z")

</div>

Hello @keyolk  
I am a bit suprised that the windows size is always 1, because that would mean that the filebeat has really low trafic or something else is off.

Before we go deeper in the debugging could you provide the following information:

- version of Filebeat
- Filebeat configuration?

Thanks

---

<div class="post-metadata">

**Author:** ![keyolk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keyolk/32/23955_2.png) [@keyolk](https://discuss.elastic.co/u/keyolk)\
**Post date:** [February 23, 2019, 2:39am UTC](https://discuss.elastic.co/t/window-size-never-grow-up/169517/3 "2019-02-23T02:39:16Z")

</div>

Hi @pierhugues  
What I assume is like below,

The filebeat process launched in docker container, with NATed network with 5 of output logstash hosts.  
At the begining it has 5 of established connection with logstash.

~~Single line of log sent to logstash, then window size become 15 from the initial window size 10, And MaxOkWindowSize also become 10.~~

Several hours later(conntracks tcp established timeout, or logstash idle timeout) without incoming log, connection to logstash is disconnected but socket is still opened.

After getting new single line of log. filebeat fails to send 5 times, windowSize shrinks to 1.  
Reopen connection, succeed to send log.  
Now windowSize is 1 and maxOkWindowSize is 2.

Again several hours pass, it fails again.  
Now windowSize and maxOkWindowSize become 1.  
It never be changed without TTL (seems it is available from v 6.0)

We use filebeat version 5.4.2 with below output configuration.

```auto
...
output.logstash:
  hosts: ${LOGSTASH_HOSTS}
  loadbalance: true
...
...

```

I think to solve it ....

- Enable TTL to refresh window size without code write.
- Implement TCP Keep-Alive
- Implement TODO part
- Try other heuristic workaround ... like
  - add 1 to maxOkWindowSize if it has same value to windowSize

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [February 27, 2019, 7:20pm UTC](https://discuss.elastic.co/t/window-size-never-grow-up/169517/4 "2019-02-27T19:20:19Z")

</div>

Before changing any code, did you look at upgrading to 6.6.x? we have changed a few things there?

---

<div class="post-metadata">

**Author:** ![keyolk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keyolk/32/23955_2.png) [@keyolk](https://discuss.elastic.co/u/keyolk)\
**Post date:** [March 5, 2019, 12:57am UTC](https://discuss.elastic.co/t/window-size-never-grow-up/169517/6 "2019-03-05T00:57:38Z")

</div>

Thanks @pierhugues I checked recent changes,  
Seems with default configuration the issue is not be reproduced.  
Only with setting "slow\_start=true" it can make same situation again.  
Is the "slow\_start mode" will be deprecated in the future ?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [March 5, 2019, 3:19pm UTC](https://discuss.elastic.co/t/window-size-never-grow-up/169517/7 "2019-03-05T15:19:48Z")

</div>

Good to hear that, concerning slow start we do not have plan to deprecated in the short term, but it's not really anymore because Logstash and Beats supports partial ACKs, so LS doesn't need to ACK the full window.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2019, 5:19pm UTC](https://discuss.elastic.co/t/window-size-never-grow-up/169517/8 "2019-04-02T17:19:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
