Logstash keeps going missing after restart due to heap size #12888
-
Version2.4.60 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU64 RAM256GB Storage for /223GB Storage for /nsm65691GB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailI have been running 2.4.60 for about a week now and my Logstash started to go missing repeatedly. I can restart it and it will come back for about a minute. The log has a couple different FATAL errors. "[FATAL][org.logstash.Logstash ] uncaught error (in thread Ruby-0-Thread-140: /usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-output-elasticsearch-11.16.0-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:216)" "[FATAL][org.logstash.Logstash ] uncaught error (in thread logstash-pipeline-flush) I have read that I need to increase the heap size, but I am unsure of where I would do that. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
The setting for that would be in |
Beta Was this translation helpful? Give feedback.
The setting for that would be in
SOC > Administration > Configuration > logstash > settings > lsheap
. Also, see https://docs.securityonion.net/en/2.4/logstash.html#lsheap