# Bad indexing performance of elasticsearch

**URL:** https://discuss.elastic.co/t/bad-indexing-performance-of-elasticsearch/37962
**Category:** Elasticsearch
**Created:** [December 25, 2015, 2:24am UTC](https://discuss.elastic.co/t/bad-indexing-performance-of-elasticsearch/37962 "2015-12-25T02:24:54Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![111110](https://avatars.discourse-cdn.com/v4/letter/1/e19adc/32.png) [@111110](https://discuss.elastic.co/u/111110)
#### Post date: [December 25, 2015, 2:24am UTC](https://discuss.elastic.co/t/bad-indexing-performance-of-elasticsearch/37962/1 "2015-12-25T02:24:55Z")

</div>

Currently, I'm using elastic search to store and query some  
logs. We set up a five node elastic search cluster. Among them two  
indexing nodes and three query nodes. In the indexing node, we have  
redis, logstash and elasticsearch on both two servers. The elasticsearch  
uses NFS storage as data store. Our requirement is to index 300 log  
entries/second. But the best performance I can get from elasticsearch is  
only 25 log entries/second!

Here's the detailed information in StackOverflow: [http://stackoverflow.com/questions/34449405/bad-indexing-performance-of-elasticsearch](http://stackoverflow.com/questions/34449405/bad-indexing-performance-of-elasticsearch)

My question is:

Can anyone tell me what is elastic search doing and why the indexing is so slow? And is it possible to improve it?

---

<div class="post-metadata">

### Author: ![111110](https://avatars.discourse-cdn.com/v4/letter/1/e19adc/32.png) [@111110](https://discuss.elastic.co/u/111110)
#### Post date: [December 25, 2015, 2:29am UTC](https://discuss.elastic.co/t/bad-indexing-performance-of-elasticsearch/37962/2 "2015-12-25T02:29:40Z")

</div>

I know that elasticsearch is not quite "compatible" with NFS. But our performance requirement is not that high, 300-400 log entries/s is enough. Plus, if don't use NFS, can we use iScsi or other kind of network storage? And if we upgrade network interface to 10G, will it be better? BTW, people will have to use local storage and can't use SAN?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 25, 2015, 2:48am UTC](https://discuss.elastic.co/t/bad-indexing-performance-of-elasticsearch/37962/3 "2015-12-25T02:48:58Z")

</div>

> [@111110](#):
>
> Among them two indexing nodes and three query nodes.

Can you explain what you mean by these?

> [@111110](#):
>
> The elasticsearch uses NFS storage as data store.

This is the cause of your problem.

---

<div class="post-metadata">

### Author: ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)
#### Post date: [December 25, 2015, 3:09am UTC](https://discuss.elastic.co/t/bad-indexing-performance-of-elasticsearch/37962/4 "2015-12-25T03:09:07Z")

</div>

> [@111110](#):
>
> if don't use NFS, can we use iScsi or other kind of network storage

Its almost certainly better to use iSCSI than NFS. Direct attached storage is going to be better if you have decent direct attached storage, but if you are with a shop that just loves their SAN then it'll do. Its unusual to use a SAN but so long as you treat it like a regular disk it should be safe.

NFS is known to cause trouble though I personally don't know the whole story. I've seen it do some horrible things in the past and I don't know if its improved since then.

---

<div class="post-metadata">

### Author: ![111110](https://avatars.discourse-cdn.com/v4/letter/1/e19adc/32.png) [@111110](https://discuss.elastic.co/u/111110)
#### Post date: [December 25, 2015, 4:56am UTC](https://discuss.elastic.co/t/bad-indexing-performance-of-elasticsearch/37962/5 "2015-12-25T04:56:05Z")

</div>

That means we have a 5 node elasticsearch cluster. 2 are dedicated to write index and 3 are exposed to customers to search.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 25, 2015, 4:57am UTC](https://discuss.elastic.co/t/bad-indexing-performance-of-elasticsearch/37962/6 "2015-12-25T04:57:29Z")

</div>

But are they client nodes, data nodes, master nodes?

---

<div class="post-metadata">

### Author: ![111110](https://avatars.discourse-cdn.com/v4/letter/1/e19adc/32.png) [@111110](https://discuss.elastic.co/u/111110)
#### Post date: [December 25, 2015, 5:05am UTC](https://discuss.elastic.co/t/bad-indexing-performance-of-elasticsearch/37962/7 "2015-12-25T05:05:03Z")

</div>

Really? I asked so cause you know iSCSI is also network storage. Will it improve performance of elasticsearch a lot?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 11:28pm UTC](https://discuss.elastic.co/t/bad-indexing-performance-of-elasticsearch/37962/8 "2017-07-05T23:28:38Z")

</div>


