# Closed+hot index or warm+hot index

**URL:** <https://discuss.elastic.co/t/closed-hot-index-or-warm-hot-index/255078>\
**Category:** Kibana\
**Tags:** ilm-index-lifecycle-management\
**Created:** [November 11, 2020, 2:11pm UTC](https://discuss.elastic.co/t/closed-hot-index-or-warm-hot-index/255078 "2020-11-11T14:11:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nyquillus](https://avatars.discourse-cdn.com/v4/letter/n/c77e96/32.png) [@nyquillus](https://discuss.elastic.co/u/nyquillus)\
**Post date:** [November 11, 2020, 2:11pm UTC](https://discuss.elastic.co/t/closed-hot-index-or-warm-hot-index/255078/1 "2020-11-11T14:11:14Z")

</div>

Hello,

I'm administrating an elastic stack at the moment and my current method right now is closing indexes older than 2 weeks and keeping the last 2 weeks in hot state. If people need to check logs older than 2 weeks they contact me and I just reopen them until they're finished. There is a considerable amount of daha flow to the stack and if I don't do reguler cleaning/closing I mostly get request timeouts from kibana. Is it better to change the older logs' states to warm/cold rather than closing? Will I notice a performance boost while querying?

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [November 11, 2020, 4:40pm UTC](https://discuss.elastic.co/t/closed-hot-index-or-warm-hot-index/255078/2 "2020-11-11T16:40:42Z")

</div>

If you are already getting request timeouts when searching hot/warm data, then that might indicate your cluster is already under stress. Are you aware that when you reopen a closed index it is reindexing based on the documents? See the docs on [closed indices](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-close.html).

Have you considered using [frozen indices](https://www.elastic.co/guide/en/elasticsearch/reference/current/frozen-indices.html) instead of closing? It would allow occasional requests on-demand, without your intervention.

Have you read the guide on [tuning for search speed](https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-search-speed.html)?

---

<div class="post-metadata">

**Author:** ![nyquillus](https://avatars.discourse-cdn.com/v4/letter/n/c77e96/32.png) [@nyquillus](https://discuss.elastic.co/u/nyquillus)\
**Post date:** [November 16, 2020, 10:56am UTC](https://discuss.elastic.co/t/closed-hot-index-or-warm-hot-index/255078/3 "2020-11-16T10:56:54Z")

</div>

Thanks for the valuable info @wylie .

I was wondering something else since I can't seem to find solid numbers anywhere. I think that my shard load can be downsized making logical groups for different indices via logstash.conf. For example let's say i have 100 different indices created each day with 1p and 1r shards and i make groups that include 3 indices each. Each group has its own identified ports and indexnames etc.

This will roughly make 33 logstash instances or 33 pipelines (again this is only a mock scenario). I will start to get a third of my shard load which will increase overall kibana/elasticsearch performance i suppose.

But will it cause logstash to consume much more memory or cpu?

Thanks.

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [November 16, 2020, 4:02pm UTC](https://discuss.elastic.co/t/closed-hot-index-or-warm-hot-index/255078/4 "2020-11-16T16:02:49Z")

</div>

I'm a Kibana developer, so I might not be able to help as much as an expert on those particular parts of the stack- feel free to ask again in the other parts of the forum. What I can point you to are some things that commonly cause performance issues:

1. Having either [too many or too few shards](https://www.elastic.co/guide/en/elasticsearch///reference/master/size-your-shards.html)
2. [Not using ILM to automate the shard sizing](https://www.elastic.co/guide/en/elasticsearch///reference/master/index-lifecycle-management.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2020, 4:02pm UTC](https://discuss.elastic.co/t/closed-hot-index-or-warm-hot-index/255078/5 "2020-12-14T16:02:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
