General security

Apache JMeter Part 4: Testing the Throughput and Performance of InfoSec Institute

October 22, 2012 by Dejan Lukan

For part 3 of this series, click here.

1. Testing the Throughput of InfoSec Institute

1.1. Running the JMeter

When everything is set-up all that is left for us to do is run the JMeter and observe the results. We can do that by simply pressing the Menu – Run – Start button.

1.2. Setting-up JMeter

Let’s present the options that we used when running the test cases in this tutorial. We used three elements, that we won’t describe in detail, since they have already been described in other parts of this tutorial series.

a) HTTP Request Defaults

We specified only the “Server Name or IP” to be

b) HTTP Request

In the HTTP Request element we specified that we want to access a resource /index.html as can be seen in the picture below:

c) Graph Result Listener

We also added the graph result listener that can show us the results of the test plan. There is no need to configure the Graph Result element, so we didn’t provide a picture.

1.3. Presenting the Results

In this section we’ll present various results we received with the JMeter when testing the performance of the web site.

First, let’s change the Ramp-up period to 0, 2, 10, 100, 1000 seconds and observe the results when simulating 1000 users and repeating the loop only once.

The picture below contains the results of performance testing with a Ramp-Up period of 0 seconds (therefore all requests are sent at once):

The picture below contains the results of performance testing with a Ramp-Up period of 2 seconds:

The picture below contains the results of performance testing with a Ramp-Up period of 10 seconds:

The picture below contains the results of performance testing with a Ramp-Up period of 100 seconds:

The picture below contains the results of performance testing with a Ramp-Up period of 1000 seconds (therefore 1 request will be sent per second):

If we take a look at the throughput we can see that in the first three cases it’s rising considerably, but in the last two it is constant. A constant throughput with a low requests/minute value means that we’ve set the ramp-up period too high, because the target application (server) can process the previous requests before the next request is even sent. This further implies that we should lower the ramp-up period to increase the load on the server.

The first case has a throughput of 429.098 requests/minute, the second case has a throughput of 416.437 requests/minute, the third case has a throughput of 1015.916 requests/minute, the fourth case has a throughput of 597.699 requests/minute and the last case has a throughput of 60.022 requests/minute. We can notice that the number of requests is increasing with the bigger ramp-up period up until some point (til fourth case). This means that when we’re sending all requests close together, the server can still process them fairly quickly, but not as fast as when we’re introducing a slight delay between the requests, which is logical.

In the above cases the best ramp-up period was somewhere in between 10 and 100 seconds. We must look for the maximum throughput, which we observed in the third use case, but we must also have a constant throughput, which we observed in the fourth use case, which implies that the best ramp-up period is somewhere in between 10 and 100 seconds.

2. Testing the Performance of InfoSec Institute

2.1. Testing with Google Statistics

In the previous parts of the JMeter tutorials we talked about measuring the best throughput with the specified average number of users we expect to be visiting the website at any given time. Normally we can do a better job than guessing a number of users that we expect to be visiting a web page at a time. We can turn to the site statistics, like Google Analytics and write down the average number of users, or better yet, the maximum number of users visiting our web page at any given time.

Google Analytics stores the following pieces of information for us:

– Total number of visits: Nt

– Total number of unique visitors: Nu

– Total number of pageviews: Np

– Average number of visited pages per visit: Na

– Total time: Tt (in seconds)

– Average time a visitor spends on the site: Tu (in seconds)

Then we must calculate the number of users per second, which we’ll directly input into our JMeter Thread Group configuration. We can calculate the number of users per second with the formula:

#Users = Nt / Tt * Tu

The obtained number will give us the average amount of users visiting our web page in any given time. We should also calculate the number of users in a time around the time when there was maximum number of users visiting our web site. This should give us the real indication of the total number of users that we must test for.

Afterward we must enter the obtained number directly into the Thread Group element in JMeter and begin our testing.

2.2. Testing without Google Statistics

Since I don’t have Google statistics that I need to perform my tests against the InfoSec Institute web site, I’ll have to resort to the method that can test the maximum number of users that can visit the mentioned web page. This will give us the best indication what the server can handle.

There is a limitation of simulating 1700 users per a desktop PC when running JMeter [1]. If we configure JMeter to use that many threads, we won’t get the most accurate results, which is why I prefer to run JMeter with at most 1000 threads per one PC. If we need to test a web page with more users than 1000, we should connect a bunch of JMeter machines together remotely [2].

The following table summarizes the number of JMeter instances we need to load the testing server with the corresponding number of users:

# Users

# Jmeter Instances

100 1
1000 1
5000 5
10000 10
50000 50

The relation between the number of users and the JMeter instances is linear, since one PC can only handle so many concurrent connections.

2.3. Manage JMeter Instances Remotely

Here we’ll take a look at how to manage Jmeter instances remotely. We’ll install two JMeter instances, one on the remote computer and the other locally. Then we’ll manage both simultaneously to run a performance test with a higher number of threads per minute than we could with only one instance.

By using JMeter we can run one JMeter GUI client that controls all the other remote JMeter instances and collects the data from them. With that we can distribute the load between multiple clients, each presenting a considerate load on the testing server.

To do that, we only need to configure one test plan, which is distributed among all remote JMeter instances, thus giving us control over all instanced from a single GUI client. The results are also presented in the GUI client so there is no need to copy the JMeter results from multiple clients over to the local machine.

2.3.1. Starting the Remote Instance

To run the JMeter remote instance, first we need to download the JMeter and extract it:

# wget

# tar xvzf apache-jmeter-2.7.tgz

# cd apache-jmeter-2.7/

If we don’t have Java installed, we need to install it. On the Ubuntu Linux distribution we can do that by executing the following command:

# apt-get install openjdk-6-jre

Afterward we can start the remote JMeter instance by issuing the command below:

# ./bin/jmeter-server

Created remote object: UnicastServerRef [liveRef: [endpoint:[](local),objID:[-2e56539d:139abf4f832:-7fff, -8592326131918894022]]]

Server failed to start: java.rmi.RemoteException: Cannot start. See server log file.

An error occurred: Cannot start. See server log file

We can see that the output is telling us that we should check the server log for a more detailed error of what happened. Ok, let’s present the jmeter-server.log:

INFO – jmeter.engine.RemoteJMeterEngineImpl: Starting backing engine on 1099

INFO – jmeter.engine.RemoteJMeterEngineImpl: IP address=

ERROR – jmeter.engine.RemoteJMeterEngineImpl: rmiregistry needs to be running to start JMeter in server mode

java.rmi.ConnectException: Connection refused to host:; nested exception is: Connection refused

An error occurred, why? It’s because the Java RMI (Remote Method Invocation) hasn’t been started yet. To automatically start it, we should edit bin/ and set the server.rmi.create variable to be true:

# From JMeter 2.3.1, the jmeter server creates the RMI registry+ as part of the server process.

# To stop the server creating the RMI registry:


When starting the jmeter-server, another error occurs:

# /.bin/jmeter-server

The jmeter-server.log contains the following debugging information:

INFO – jmeter.engine.RemoteJMeterEngineImpl: Starting backing engine on 1099

INFO – jmeter.engine.RemoteJMeterEngineImpl: IP address=

INFO – jmeter.engine.RemoteJMeterEngineImpl: Creating RMI registry (server.rmi.create=true)

ERROR – jmeter.engine.RemoteJMeterEngineImpl: rmiregistry needs to be running to start JMeter in server mode

java.rmi.ServerException: RemoteException occurred in server thread; nested exception is:

java.rmi.AccessException: Registry.Registry.rebind disallowed; origin / is non-local host

The above error happened because our hostname points to our WAN IP not LAN IP, thus giving us the IP of a router, which is If we want to start jmeter-server we need to change the /etc/hosts and edit our hostname to point to our local address like the output below:

Instead of:

After that the server starts normally:

# ./bin/jmeter-server

Created remote object: UnicastServerRef [liveRef: [endpoint:[](local),objID:[-5549f37:139ac0cbbed:-7fff, 6781158136036771797]]]

And it’s listening on port 1099:

# netstat -landtp

tcp6 0 0 ESTABLISHED 17995/java

2.3.2. Starting the GUI Client Instance

On the controlling machine, edit the and change the remote_hosts variable to hold the IP addresses of all remote JMeter instances, like below:


Then we can start the local GUI JMeter normally, but we’ll be able to use multiple remote JMeter instances by clicking on Run – Remote Start and choosing the appropriate remote JMeter instance. We can start individual JMeter remote instances or we can start them all at the same time. In any case, each remote JMeter instance will proceed and execute the whole test plan defined in the local GUI JMeter.

For this to work, we need to ensure that a couple of ports are open and not firewalled, regardless of whether we’re doing the performance testing on a local network or over the Internet. Each JMeter remote instance will have to have the port 1099 open for the client GUI JMeter to be able to connect to the remote JMeter instance. But in addition to this, a reverse connection is also required to return the results from the remote JMeter instance to the client GUI instance. By default the JMeter uses a random high-numbered port, but this can be adjusted with the client.rmi.localport variable in

The following picture summarizes the appropriate variables and ports that need to be open when connecting from localhost GUI JMeter to remote JMeter instance.

3. Conclusion

We’ve seen how to determine the best ramp-up period to use when testing the performance of a web page. We also measured the performance of a web site by analyzing the results and looking for the best throughput; the best throughput means the maximum number of requests/minute the web site can handle.

We’ve also looked at the remote JMeter testing, which we can use to present a bigger load on the testing server.


[1] Jmeter threads test failed, accessible on

[2] Jmeter threads, accessible on

Posted: October 22, 2012
Dejan Lukan
View Profile

Dejan Lukan is a security researcher for InfoSec Institute and penetration tester from Slovenia. He is very interested in finding new bugs in real world software products with source code analysis, fuzzing and reverse engineering. He also has a great passion for developing his own simple scripts for security related problems and learning about new hacking techniques. He knows a great deal about programming languages, as he can write in couple of dozen of them. His passion is also Antivirus bypassing techniques, malware research and operating systems, mainly Linux, Windows and BSD. He also has his own blog available here:

3 responses to “Apache JMeter Part 4: Testing the Throughput and Performance of InfoSec Institute”

  1. Ophir Prusak says:

    Great series on JMeter.

    One of the trends I am seeing is that users are first doing load testing on a single, in-house machine but when they need to test with a larger load (and thus need several JMeter instances) it’s much simpler to use a paid service that provides JMeter instances as a service using a service like provides (Note – I work BlazeMeter) which is basically JMeter as a service on steroids.

  2. Dejan Lukan (eleanor) says:

    Hi, thank you for the good review. Regarding BlazeMeter, I have come across it, but haven’t included in the article; I don’t know exactly why not (I could have described it in a sentence or two). Anyway, the main reason I prefer using my own computers is the following: each computer can simulate about 1000 concurrent users. So, if I would like to simulate 5000 concurrent users, I would need to pay $400 for 1 month on BlazeMeter, which is pretty expensive and I always have about 5 computers lying around; if I don’t, my friends do. I would love to use the BlazeMeter if it would be a little bit cheaper: I wouldn’t mind spending like $100 per 1 month per 5000 users.

  3. RS says:

    I was searching google on how to create “Scenarios” with Jmeter and landed here. This is nice and rich article, as very few sites on such topic.

    But can you please guide how can i create a full-fledged scenario in JMeter?
    Scenario here means say user registration & Profile setting:

    Action 1 – Visit Home Page (waits for few seconds *Think Time*)
    Action 2 – User clicks register link (Think Time)
    Action 3 – User fills form (Think Time) and submits
    Action 4 – User is redirected to profile page where he/she can see profile (Think Time)
    Action 5 – User logs out and exits.

    Now, i am asked to provide the TPH for this single scenario and also the Action-wise Response time(90th Percetile).
    How can i do this with JMeter?

    PS. I don’t want object-level response time eg. say response time of individual css/jpg/embedded object. Is it possible?

    Plz replay…..

Leave a Reply

Your email address will not be published.