# Bad performance on aggregations

**URL:** <https://discuss.elastic.co/t/bad-performance-on-aggregations/22359>\
**Category:** Elasticsearch\
**Created:** [February 24, 2015, 3:28pm UTC](https://discuss.elastic.co/t/bad-performance-on-aggregations/22359 "2015-02-24T15:28:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Octavian](https://avatars.discourse-cdn.com/v4/letter/o/54ee81/32.png) [@Octavian](https://discuss.elastic.co/u/Octavian)\
**Post date:** [February 24, 2015, 3:28pm UTC](https://discuss.elastic.co/t/bad-performance-on-aggregations/22359/1 "2015-02-24T15:28:50Z")

</div>

Hello,

I have a problem with the performance of aggregations: The time of the  
aggregation is very worst.

I'm doing the next aggregation over an index with 160M documents (16G of  
data).

{  
"query": {  
"filtered": {  
"filter": {  
"range": {  
"\_cache": false,  
"insert\_date": {  
"gte": 1424790449432  
}  
}  
}  
}  
},  
"aggs": {  
"tag": {  
"terms": {  
"field": "origin\_ip"  
}  
}  
}  
}

Time: 18s. No results found (The result is correct. There are no documents  
with insert\_date greater than 1424790449432)

However if I'm doing the next search:  
{  
"query": {  
"filtered": {  
"filter": {  
"range": {  
"\_cache": false,  
"insert\_date": {  
"gte": 1424790449432  
}  
}  
}  
}  
}  
}

Time: 7ms . No results found. (As I already wrote, the result is correct).

What is happening?

In documentation  
([http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/\_filtered\_query.html](http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/_filtered_query.html)),  
it is written :"The query (which happens to include a filter) returns a  
certain subset of documents, and the aggregation operates on those  
documents."

In my situation, there are no elements in the subset of documents returned  
by the filter, so the aggregation should run in the same amount of time  
like the search.

So, how can I improve the performance of that aggregation?

Thank you,

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/1d1d559a-7ebe-435f-be9c-5dd89528eb2d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1d1d559a-7ebe-435f-be9c-5dd89528eb2d%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Octavian](https://avatars.discourse-cdn.com/v4/letter/o/54ee81/32.png) [@Octavian](https://discuss.elastic.co/u/Octavian)\
**Post date:** [February 24, 2015, 3:30pm UTC](https://discuss.elastic.co/t/bad-performance-on-aggregations/22359/2 "2015-02-24T15:30:09Z")

</div>

BTW, I'm running ES 1.4.2 with Java 7

On Tuesday, February 24, 2015 at 5:28:50 PM UTC+2, Octavian wrote:

> Hello,
> 
> I have a problem with the performance of aggregations: The time of the  
> aggregation is very worst.
> 
> I'm doing the next aggregation over an index with 160M documents (16G of  
> data).
> 
> {  
> "query": {  
> "filtered": {  
> "filter": {  
> "range": {  
> "\_cache": false,  
> "insert\_date": {  
> "gte": 1424790449432  
> }  
> }  
> }  
> }  
> },  
> "aggs": {  
> "tag": {  
> "terms": {  
> "field": "origin\_ip"  
> }  
> }  
> }  
> }
> 
> Time: 18s. No results found (The result is correct. There are no documents  
> with insert\_date greater than 1424790449432)
> 
> However if I'm doing the next search:  
> {  
> "query": {  
> "filtered": {  
> "filter": {  
> "range": {  
> "\_cache": false,  
> "insert\_date": {  
> "gte": 1424790449432  
> }  
> }  
> }  
> }  
> }  
> }
> 
> Time: 7ms . No results found. (As I already wrote, the result is correct).
> 
> What is happening?
> 
> In documentation (  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/_filtered_query.html)),  
> it is written :"The query (which happens to include a filter) returns a  
> certain subset of documents, and the aggregation operates on those  
> documents."
> 
> In my situation, there are no elements in the subset of documents returned  
> by the filter, so the aggregation should run in the same amount of time  
> like the search.
> 
> So, how can I improve the performance of that aggregation?
> 
> Thank you,

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/62bfec72-b9b8-4c18-b78d-18bd6f211ab2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/62bfec72-b9b8-4c18-b78d-18bd6f211ab2%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Octavian](https://avatars.discourse-cdn.com/v4/letter/o/54ee81/32.png) [@Octavian](https://discuss.elastic.co/u/Octavian)\
**Post date:** [March 4, 2015, 11:20am UTC](https://discuss.elastic.co/t/bad-performance-on-aggregations/22359/3 "2015-03-04T11:20:13Z")

</div>

Hello,

Can anybody help me on this problem? Is this a known bug in Elasticsearch?

Thank you

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e1bf4a18-77d0-4ba8-a3b1-4832494a6050%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e1bf4a18-77d0-4ba8-a3b1-4832494a6050%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![savioteles](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/savioteles/32/851_2.png) [@savioteles](https://discuss.elastic.co/u/savioteles)\
**Post date:** [March 4, 2015, 2:33pm UTC](https://discuss.elastic.co/t/bad-performance-on-aggregations/22359/4 "2015-03-04T14:33:10Z")

</div>

What is the Elasticsearch JAVA params (like heap size)? Try using range  
date query

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

.

2015-03-04 8:20 GMT-03:00 Octavian [octavian.rinciog@gmail.com](mailto:octavian.rinciog@gmail.com):

> Hello,
> 
> Can anybody help me on this problem? Is this a known bug in Elasticsearch?
> 
> Thank you
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/e1bf4a18-77d0-4ba8-a3b1-4832494a6050%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e1bf4a18-77d0-4ba8-a3b1-4832494a6050%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/e1bf4a18-77d0-4ba8-a3b1-4832494a6050%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/e1bf4a18-77d0-4ba8-a3b1-4832494a6050%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
Regards,

Sávio S. Teles de Oliveira

Co-Founder & Software Engineer at [www.gogeo.io](http://www.gogeo.io).  
PHD student in Computer Science focusing on High Performance Maps Platform  
and Spatial Algorithms.  
voice: +55 62 9136 6996  
[http://br.linkedin.com/in/savioteles](http://br.linkedin.com/in/savioteles)  
[https://twitter.com/savioteless](https://twitter.com/savioteless)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAFKmhPuC-UHQmpKboEDzLz0TFra8U%2Bzng5zgbzT\_A2RoCEgDNA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAFKmhPuC-UHQmpKboEDzLz0TFra8U%2Bzng5zgbzT_A2RoCEgDNA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [March 4, 2015, 5:02pm UTC](https://discuss.elastic.co/t/bad-performance-on-aggregations/22359/5 "2015-03-04T17:02:40Z")

</div>

What do the hot threads look like while the query is running?

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

On Tue, Feb 24, 2015 at 4:28 PM, Octavian [octavian.rinciog@gmail.com](mailto:octavian.rinciog@gmail.com)  
wrote:

> Hello,
> 
> I have a problem with the performance of aggregations: The time of the  
> aggregation is very worst.
> 
> I'm doing the next aggregation over an index with 160M documents (16G of  
> data).
> 
> {  
> "query": {  
> "filtered": {  
> "filter": {  
> "range": {  
> "\_cache": false,  
> "insert\_date": {  
> "gte": 1424790449432  
> }  
> }  
> }  
> }  
> },  
> "aggs": {  
> "tag": {  
> "terms": {  
> "field": "origin\_ip"  
> }  
> }  
> }  
> }
> 
> Time: 18s. No results found (The result is correct. There are no documents  
> with insert\_date greater than 1424790449432)
> 
> However if I'm doing the next search:  
> {  
> "query": {  
> "filtered": {  
> "filter": {  
> "range": {  
> "\_cache": false,  
> "insert\_date": {  
> "gte": 1424790449432  
> }  
> }  
> }  
> }  
> }  
> }
> 
> Time: 7ms . No results found. (As I already wrote, the result is correct).
> 
> What is happening?
> 
> In documentation (  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/_filtered_query.html)),  
> it is written :"The query (which happens to include a filter) returns a  
> certain subset of documents, and the aggregation operates on those  
> documents."
> 
> In my situation, there are no elements in the subset of documents returned  
> by the filter, so the aggregation should run in the same amount of time  
> like the search.
> 
> So, how can I improve the performance of that aggregation?
> 
> Thank you,
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/1d1d559a-7ebe-435f-be9c-5dd89528eb2d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1d1d559a-7ebe-435f-be9c-5dd89528eb2d%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/1d1d559a-7ebe-435f-be9c-5dd89528eb2d%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/1d1d559a-7ebe-435f-be9c-5dd89528eb2d%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j4S6AwmgjY-T9u5EaH9RoL%2B-A3JHucAMYtpYyqFAHp50w%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j4S6AwmgjY-T9u5EaH9RoL%2B-A3JHucAMYtpYyqFAHp50w%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:28am UTC](https://discuss.elastic.co/t/bad-performance-on-aggregations/22359/6 "2017-07-06T00:28:33Z")

</div>


