# Architecture to prevent slow queries

**URL:** <https://discuss.elastic.co/t/architecture-to-prevent-slow-queries/20086>\
**Category:** Elasticsearch\
**Created:** [October 6, 2014, 8:28am UTC](https://discuss.elastic.co/t/architecture-to-prevent-slow-queries/20086 "2014-10-06T08:28:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael\_Irwin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_irwin/32/985_2.png) [@Michael\_Irwin](https://discuss.elastic.co/u/Michael_Irwin)\
**Post date:** [October 6, 2014, 8:28am UTC](https://discuss.elastic.co/t/architecture-to-prevent-slow-queries/20086/1 "2014-10-06T08:28:31Z")

</div>

I'm using ES for searching for events based on date and geo distance, as  
well as textual content. I'm also using logstash for handling app logging  
and analytics.

I've noticed after I have millions of records from logging/analytics, the  
events search starts slowing down.

I'm currently using just one node (testing all of this out before going  
into production). The event data is currently stored in just one index.

My question is, what is a good way to handle this scenario to prevent event  
searches from becoming slow? Should I use separate nodes just for  
logging/analytics? Should I index the event data differently?

Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/1b54b0a5-afbf-4c5e-b19d-e169b2aea824%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1b54b0a5-afbf-4c5e-b19d-e169b2aea824%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Michael\_Irwin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_irwin/32/985_2.png) [@Michael\_Irwin](https://discuss.elastic.co/u/Michael_Irwin)\
**Post date:** [October 6, 2014, 8:30am UTC](https://discuss.elastic.co/t/architecture-to-prevent-slow-queries/20086/2 "2014-10-06T08:30:12Z")

</div>

Also, I would be grateful if someone could point me to some good general  
information about this kind of thing.

On Monday, October 6, 2014 4:28:31 AM UTC-4, Michael Irwin wrote:

> I'm using ES for searching for events based on date and geo distance, as  
> well as textual content. I'm also using logstash for handling app logging  
> and analytics.
> 
> I've noticed after I have millions of records from logging/analytics, the  
> events search starts slowing down.
> 
> I'm currently using just one node (testing all of this out before going  
> into production). The event data is currently stored in just one index.
> 
> My question is, what is a good way to handle this scenario to prevent  
> event searches from becoming slow? Should I use separate nodes just for  
> logging/analytics? Should I index the event data differently?
> 
> Thanks!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a9b5f1d8-28a8-464f-a9fd-21b6f0a61d65%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a9b5f1d8-28a8-464f-a9fd-21b6f0a61d65%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [October 6, 2014, 8:43am UTC](https://discuss.elastic.co/t/architecture-to-prevent-slow-queries/20086/3 "2014-10-06T08:43:51Z")

</div>

Just add nodes. That's all 🙂

Jörg

On Mon, Oct 6, 2014 at 10:30 AM, Michael Irwin [mdi@livej.am](mailto:mdi@livej.am) wrote:

> Also, I would be grateful if someone could point me to some good general  
> information about this kind of thing.
> 
> On Monday, October 6, 2014 4:28:31 AM UTC-4, Michael Irwin wrote:
> 
> > I'm using ES for searching for events based on date and geo distance, as  
> > well as textual content. I'm also using logstash for handling app logging  
> > and analytics.
> > 
> > I've noticed after I have millions of records from logging/analytics, the  
> > events search starts slowing down.
> > 
> > I'm currently using just one node (testing all of this out before going  
> > into production). The event data is currently stored in just one index.
> > 
> > My question is, what is a good way to handle this scenario to prevent  
> > event searches from becoming slow? Should I use separate nodes just for  
> > logging/analytics? Should I index the event data differently?
> > 
> > Thanks!
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/a9b5f1d8-28a8-464f-a9fd-21b6f0a61d65%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a9b5f1d8-28a8-464f-a9fd-21b6f0a61d65%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/a9b5f1d8-28a8-464f-a9fd-21b6f0a61d65%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/a9b5f1d8-28a8-464f-a9fd-21b6f0a61d65%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAKdsXoE9sY7EQ%2BWe-RsTcQMNUv%3DvcDRpi6iCTRhk%2BB%3Dv8%3Dx4VA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAKdsXoE9sY7EQ%2BWe-RsTcQMNUv%3DvcDRpi6iCTRhk%2BB%3Dv8%3Dx4VA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [October 6, 2014, 12:35pm UTC](https://discuss.elastic.co/t/architecture-to-prevent-slow-queries/20086/4 "2014-10-06T12:35:22Z")

</div>

You could run less intense queries. Get more ram. Finally if io wait is a  
problem then you could switch to/add more solid state disks. Or you can  
add more nodes. We've done all of those for our Elasticsearch (no  
Logstash/Kibana in front though).

Nik

On Mon, Oct 6, 2014 at 4:43 AM, [joergprante@gmail.com](mailto:joergprante@gmail.com) \<[joergprante@gmail.com](mailto:joergprante@gmail.com)

> wrote:

> Just add nodes. That's all 🙂
> 
> Jörg
> 
> On Mon, Oct 6, 2014 at 10:30 AM, Michael Irwin [mdi@livej.am](mailto:mdi@livej.am) wrote:
> 
> > Also, I would be grateful if someone could point me to some good general  
> > information about this kind of thing.
> > 
> > On Monday, October 6, 2014 4:28:31 AM UTC-4, Michael Irwin wrote:
> > 
> > > I'm using ES for searching for events based on date and geo distance, as  
> > > well as textual content. I'm also using logstash for handling app logging  
> > > and analytics.
> > > 
> > > I've noticed after I have millions of records from logging/analytics,  
> > > the events search starts slowing down.
> > > 
> > > I'm currently using just one node (testing all of this out before going  
> > > into production). The event data is currently stored in just one index.
> > > 
> > > My question is, what is a good way to handle this scenario to prevent  
> > > event searches from becoming slow? Should I use separate nodes just for  
> > > logging/analytics? Should I index the event data differently?
> > > 
> > > Thanks!
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/a9b5f1d8-28a8-464f-a9fd-21b6f0a61d65%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a9b5f1d8-28a8-464f-a9fd-21b6f0a61d65%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/a9b5f1d8-28a8-464f-a9fd-21b6f0a61d65%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/a9b5f1d8-28a8-464f-a9fd-21b6f0a61d65%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> > 
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/CAKdsXoE9sY7EQ%2BWe-RsTcQMNUv%3DvcDRpi6iCTRhk%2BB%3Dv8%3Dx4VA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAKdsXoE9sY7EQ%2BWe-RsTcQMNUv%3DvcDRpi6iCTRhk%2BB%3Dv8%3Dx4VA%40mail.gmail.com)  
> [https://groups.google.com/d/msgid/elasticsearch/CAKdsXoE9sY7EQ%2BWe-RsTcQMNUv%3DvcDRpi6iCTRhk%2BB%3Dv8%3Dx4VA%40mail.gmail.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/CAKdsXoE9sY7EQ%2BWe-RsTcQMNUv%3DvcDRpi6iCTRhk%2BB%3Dv8%3Dx4VA%40mail.gmail.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAPmjWd0O1PH1w8Duhb-4DZ5e3scAcZzTZRkMFByx8rrezakLeg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAPmjWd0O1PH1w8Duhb-4DZ5e3scAcZzTZRkMFByx8rrezakLeg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:58am UTC](https://discuss.elastic.co/t/architecture-to-prevent-slow-queries/20086/5 "2017-07-06T00:58:07Z")

</div>


