# X-Pack monitoring using up a lot of CPU

**URL:** <https://discuss.elastic.co/t/x-pack-monitoring-using-up-a-lot-of-cpu/133074>\
**Category:** Elasticsearch\
**Created:** [May 24, 2018, 5:41am UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-up-a-lot-of-cpu/133074 "2018-05-24T05:41:59Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![JensVanDeynse](https://avatars.discourse-cdn.com/v4/letter/j/3d9bf3/32.png) [@JensVanDeynse](https://discuss.elastic.co/u/JensVanDeynse)\
**Post date:** [May 24, 2018, 5:42am UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-up-a-lot-of-cpu/133074/1 "2018-05-24T05:42:00Z")

</div>

Hello there

In our company we've set up an elasticstack which has to handle about 130GB of logs (in indices) per day coming from 14 hosts (for now).  
Yesterday I install x-pack monitoring on the filebeats but then I noticed that the CPU usage of the elasticsearch nodes (2) began to rise significantly.

It is a know issue that enabling filebeat monitoring needs a lot of CPU resources? If so, is there a fix for this?  
If not, does anybody have any idea why the CPU usage would suddenly start to spike?

Any help or tips would be appreciated  
Thank you

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [May 24, 2018, 11:54am UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-up-a-lot-of-cpu/133074/2 "2018-05-24T11:54:33Z")

</div>

Monitoring should add some overhead to CPU usage, but it shouldn't be that significant. Can you try and reduce the interval at which the Filebeat monitoring is sending data and see if that makes a difference?  
Also, can you show us some screenshots from the ES monitoring charts to show what kind of increase in CPU usage we're talking about. It sounds like something worth investigating further.

---

<div class="post-metadata">

**Author:** ![JensVanDeynse](https://avatars.discourse-cdn.com/v4/letter/j/3d9bf3/32.png) [@JensVanDeynse](https://discuss.elastic.co/u/JensVanDeynse)\
**Post date:** [May 24, 2018, 1:50pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-up-a-lot-of-cpu/133074/3 "2018-05-24T13:50:28Z")

</div>

How can I reduce this interval, I didn't find a lot of info about x-pack monitoring for filebeat

Next to this I know that the CPU usage doubled and this is mainly 'User CPU time' but I'm not sure if the cause is X-pack since this is still an initial setup and changes are made daily.

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [May 24, 2018, 5:21pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-up-a-lot-of-cpu/133074/4 "2018-05-24T17:21:24Z")

</div>

On another note, have you considered not collecting X-Pack monitoring data into your production cluster but having it on its own dedicated Elasticsearch cluster? Say in the event that production has an issue and the monitoring data is unavailable which does not aid towards resolution.

That second off production cluster gives insight during these periods.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [May 24, 2018, 5:36pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-up-a-lot-of-cpu/133074/5 "2018-05-24T17:36:22Z")

</div>

`xpack.monitoring.collection.interval` is the setting used by monitoring for Kibana and ES so it should be the same for Filebeat.  
But if you change it, also change x`pack.monitoring.min_interval_seconds` option in kibana.yml to the same value.  
The default interval is 10s. Change it to something that will fit your business needs, maybe 30s or 60s.

---

<div class="post-metadata">

**Author:** ![JensVanDeynse](https://avatars.discourse-cdn.com/v4/letter/j/3d9bf3/32.png) [@JensVanDeynse](https://discuss.elastic.co/u/JensVanDeynse)\
**Post date:** [May 29, 2018, 12:02pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-up-a-lot-of-cpu/133074/6 "2018-05-29T12:02:03Z")

</div>

Allright, I'll give that a shot and see how it goes but I don't think solely x-pack is the problem  
Now the CPU has calmed down a bit but is still higher than without monitoring

---

<div class="post-metadata">

**Author:** ![JensVanDeynse](https://avatars.discourse-cdn.com/v4/letter/j/3d9bf3/32.png) [@JensVanDeynse](https://discuss.elastic.co/u/JensVanDeynse)\
**Post date:** [May 29, 2018, 12:03pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-up-a-lot-of-cpu/133074/7 "2018-05-29T12:03:39Z")

</div>

We didn't consider that because we are currently only using a basic license (looking for information before upgrading) so I just enabled the monitoring for some basic statistics

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2018, 12:12pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-up-a-lot-of-cpu/133074/8 "2018-06-26T12:12:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
