# After query, Kibana unresponsive

**URL:** <https://discuss.elastic.co/t/after-query-kibana-unresponsive/45577>\
**Category:** Kibana\
**Created:** [March 28, 2016, 10:17am UTC](https://discuss.elastic.co/t/after-query-kibana-unresponsive/45577 "2016-03-28T10:17:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![petar.kozic](https://avatars.discourse-cdn.com/v4/letter/p/ccd318/32.png) [@petar.kozic](https://discuss.elastic.co/u/petar.kozic)\
**Post date:** [March 28, 2016, 10:17am UTC](https://discuss.elastic.co/t/after-query-kibana-unresponsive/45577/1 "2016-03-28T10:17:03Z")

</div>

Hi,

I have ELK stack with one node (master). I will pipe logs from about 10 servers, about 500.000 logs in 12 hours.

Hardware:  
VPS (6 CPU)  
Memory: 15GB  
Heap size: 8GB  
Swappoff

I have problem when I try to search some query in Kibana.  
e.g. I first choose Absolutly date, about 2 days. I see about 1.500.000 hits (logs).  
Match filter only one input type. I see about 700 hits (logs)  
When I input query one word, e.g backup or "backup complete" or something else, Kibana goes to unresponsive mode. I must to Kill browser.

Disk I/O is small, CPU utilization small, Memory free 12GB.  
Please help me. Thank you.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [March 28, 2016, 2:15pm UTC](https://discuss.elastic.co/t/after-query-kibana-unresponsive/45577/2 "2016-03-28T14:15:18Z")

</div>

Hi Petar,

What versions of Elasticsearch and Kibana are you running? And what OS are you on?

Can you check Kibana and Elasticsearch logs to see if there's any clues there?

When you say "Kibana goes to unresponsive mode" do you mean you get the message like "a script is not responding do you want to wait or close" (might be different on different browsers)?

In your browser, you could hit F12 and start the Network tool. Then if you try your query again you should see what the request is that Kibana made to Elasticsearch. That might help us figure out what the problem is.

Thanks,  
Lee

---

<div class="post-metadata">

**Author:** ![petar.kozic](https://avatars.discourse-cdn.com/v4/letter/p/ccd318/32.png) [@petar.kozic](https://discuss.elastic.co/u/petar.kozic)\
**Post date:** [March 28, 2016, 2:44pm UTC](https://discuss.elastic.co/t/after-query-kibana-unresponsive/45577/3 "2016-03-28T14:44:10Z")

</div>

Dear,

Elastic version:

{  
"name" : "Dougboy",  
"cluster\_name" : "elasticsearch",  
"version" : {  
"number" : "2.2.1",  
"build\_hash" : "d045fc29d1932bce18b2e65ab8b297fbf6cd41a1",  
"build\_timestamp" : "2016-03-09T09:38:54Z",  
"build\_snapshot" : false,  
"lucene\_version" : "5.4.1"  
},  
"tagline" : "You Know, for Search"  
}

Kibana version: 4.4.2

I can`t open Inspect (F12) Network tool, because whole Tab in Chrome is not responsive. After a couple seconds I can click on Wait or Kill.

In Logstash and Kibana logs I haven't error or warning.

OS is Linux Ubuntu 14.04 LTS.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [March 28, 2016, 3:45pm UTC](https://discuss.elastic.co/t/after-query-kibana-unresponsive/45577/4 "2016-03-28T15:45:21Z")

</div>

Hi Petar,

Start the browser (F12) Network tool before you do your query for "backup".

Thanks,  
Lee

---

<div class="post-metadata">

**Author:** ![petar.kozic](https://avatars.discourse-cdn.com/v4/letter/p/ccd318/32.png) [@petar.kozic](https://discuss.elastic.co/u/petar.kozic)\
**Post date:** [March 29, 2016, 6:56am UTC](https://discuss.elastic.co/t/after-query-kibana-unresponsive/45577/5 "2016-03-29T06:56:09Z")

</div>

Hi Lee,

I found what is problem. I use IMAP plugin for mail. I receive some report email from some backup with text attachment that has about 15 pages text. When I want to search something in that index Kibana stop responding.

Does it have some way to exclude attachment in received mail with IMAP plugin filter ?

Thank you Lee.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [March 29, 2016, 1:30pm UTC](https://discuss.elastic.co/t/after-query-kibana-unresponsive/45577/6 "2016-03-29T13:30:39Z")

</div>

Hi Petar,

I'm glad you found the problem.  
I've never heard of the IMAP plugin filter. Is it a Logstash thing? You might have to search and/or ask a question on that Discuss page. [https://discuss.elastic.co/c/logstash](https://discuss.elastic.co/c/logstash)

Thanks,  
Lee

---

<div class="post-metadata">

**Author:** ![petar.kozic](https://avatars.discourse-cdn.com/v4/letter/p/ccd318/32.png) [@petar.kozic](https://discuss.elastic.co/u/petar.kozic)\
**Post date:** [March 29, 2016, 2:08pm UTC](https://discuss.elastic.co/t/after-query-kibana-unresponsive/45577/7 "2016-03-29T14:08:27Z")

</div>

Yes, Logstash.  
Ok thank you very much.

I will post my problme with IMAP plugin in Logstash discuss.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:57pm UTC](https://discuss.elastic.co/t/after-query-kibana-unresponsive/45577/8 "2017-07-06T13:57:38Z")

</div>


