Logstash
By default, Logstash uses in-memory bounded queues between pipeline stages (inputs → pipeline workers) to buffer events.
Platforms: Linux · Last verified September 6, 2026
By default, Logstash uses in-memory bounded queues between pipeline stages (inputs → pipeline workers) to buffer events. The size of these in-memory queues is fixed and not configurable.
Only use this tool against systems you own or are explicitly authorized to test — see the disclaimer.
Getting started
Bundled with Security Onion. See Security Onion's official tool documentation and upstream website linked above for details.
