Skip to content
Discussion options

You must be logged in to vote

From the metrics you sent, IMO the slowdown is probably coming from disk writes on the HDD storage. Logstash is reporting that the malcolm-input pipeline workers are 100% blocked, which usually means they’re waiting on something downstream rather than being busy with CPU work. On the OpenSearch side, the cluster stats show very low CPU usage and no queued or rejected write tasks, so it doesn’t look like OpenSearch itself is overloaded. That usually leaves disk I/O as the limiting factor. Your iostat output shows the main disk sitting around 50-75% utilization, and since both Logstash’s persistent queue and OpenSearch indexing are writing to the same shared HDD storage, they’re competing f…

Replies: 7 comments 1 reply

Comment options

mmguero
Mar 4, 2026
Maintainer Author

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@Bletcherous-Game-Development
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

mmguero
Mar 4, 2026
Maintainer Author

You must be logged in to vote
0 replies
Answer selected by mmguero
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
logstash Relating to Malcolm's use of Logstash performance Related to speed/performance
2 participants