# Constant timeouts querying Packetbeat indices

**URL:** <https://discuss.elastic.co/t/constant-timeouts-querying-packetbeat-indices/123897>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [March 14, 2018, 12:19pm UTC](https://discuss.elastic.co/t/constant-timeouts-querying-packetbeat-indices/123897 "2018-03-14T12:19:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wanderer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wanderer/32/55140_2.png) [@Wanderer](https://discuss.elastic.co/u/Wanderer)\
**Post date:** [March 14, 2018, 12:19pm UTC](https://discuss.elastic.co/t/constant-timeouts-querying-packetbeat-indices/123897/1 "2018-03-14T12:19:50Z")

</div>

We're running one ES/Kibana server and pulling in Filebeat, Metricbeat and Packetbeat data. The Filebeat and Metricbeat indices are a few hundred MB and run fine but Packetbeat indicies are several GB. When we include Packetbeat indices in Discover queries we get timeouts and the CPU spikes for long periods. I can increase the Kibana timeout to mask the problem. I've removed flow data to decrease the size of the indices but even searching for a 30 minute window causes timeouts in Kibana.

Error: Gateway Timeout  
at respond ([https://es-data.veerotech.net/bundles/vendors.bundle.js?v=16588:111:161556](https://es-data.veerotech.net/bundles/vendors.bundle.js?v=16588:111:161556))  
at checkRespForFailure ([https://es-data.veerotech.net/bundles/vendors.bundle.js?v=16588:111:160796](https://es-data.veerotech.net/bundles/vendors.bundle.js?v=16588:111:160796))  
at [https://servername/bundles/vendors.bundle.js?v=16588:105:285566](https://servername/bundles/vendors.bundle.js?v=16588:105:285566)  
at processQueue ([https://servername/bundles/vendors.bundle.js?v=16588:58:132456](https://servername/bundles/vendors.bundle.js?v=16588:58:132456))  
at [https://servername/bundles/vendors.bundle.js?v=16588:58:133349](https://servername/bundles/vendors.bundle.js?v=16588:58:133349)  
at Scope.$digest ([https://servername/bundles/vendors.bundle.js?v=16588:58:144239](https://servername/bundles/vendors.bundle.js?v=16588:58:144239))  
at Scope.$apply ([https://servername/bundles/vendors.bundle.js?v=16588:58:147018](https://servername/bundles/vendors.bundle.js?v=16588:58:147018))  
at done ([https://servername/bundles/vendors.bundle.js?v=16588:58:100026](https://servername/bundles/vendors.bundle.js?v=16588:58:100026))  
at completeRequest ([https://servername/bundles/vendors.bundle.js?v=16588:58:104697](https://servername/bundles/vendors.bundle.js?v=16588:58:104697))  
at XMLHttpRequest.xhr.onload ([https://servername/bundles/vendors.bundle.js?v=16588:58:105435](https://servername/bundles/vendors.bundle.js?v=16588:58:105435))

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 15, 2018, 11:39am UTC](https://discuss.elastic.co/t/constant-timeouts-querying-packetbeat-indices/123897/2 "2018-03-15T11:39:12Z")

</div>

What happens if you run the queries directly against Elasticsearch? What is your Elasticsearch cluster size? I'm wondering if you hit an issue on the Elasticsearch or Kibana side.

---

<div class="post-metadata">

**Author:** ![Wanderer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wanderer/32/55140_2.png) [@Wanderer](https://discuss.elastic.co/u/Wanderer)\
**Post date:** [March 15, 2018, 12:51pm UTC](https://discuss.elastic.co/t/constant-timeouts-querying-packetbeat-indices/123897/3 "2018-03-15T12:51:19Z")

</div>

We are rookies at this 🙂 . Can you point me to where I can find how to do this in the docs please?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 16, 2018, 1:16pm UTC](https://discuss.elastic.co/t/constant-timeouts-querying-packetbeat-indices/123897/4 "2018-03-16T13:16:59Z")

</div>

So basically the question is how many Elasticsearch nodes have you deployed with how much memory? And what is the size of your indices? [https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-stats.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-stats.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2018, 1:17pm UTC](https://discuss.elastic.co/t/constant-timeouts-querying-packetbeat-indices/123897/5 "2018-04-13T13:17:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
