# Discover query : timeout after a 99h treshold

**URL:** <https://discuss.elastic.co/t/discover-query-timeout-after-a-99h-treshold/121083>\
**Category:** Elasticsearch\
**Created:** [February 22, 2018, 4:08pm UTC](https://discuss.elastic.co/t/discover-query-timeout-after-a-99h-treshold/121083 "2018-02-22T16:08:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Retenodus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/retenodus/32/28063_2.png) [@Retenodus](https://discuss.elastic.co/u/Retenodus)\
**Post date:** [February 22, 2018, 4:08pm UTC](https://discuss.elastic.co/t/discover-query-timeout-after-a-99h-treshold/121083/1 "2018-02-22T16:08:16Z")

</div>

Hello,

I have one index a day in Elasticsearch (6.1) and using Kibana (with defaults parameters), I try to do a query on several days in the discover tab. It works for the 4 last days (99h exactly) and in the response, Elasticsearch says it took ~6s, hitting 12 000 000 events. The response is 1.3M characters, which means ~10Mbits.

With 5 days or more (or even 100 hours), I hit a 30s timeout. I don't know what is the issue here:

- Kibana does not have any specific logs.
- None of my elasticsearch servers seems to have any issue with any resources (heap, ram, cpu, io, network, load)
- Whether I query for 2 days or 99 hours, there is no big changes in the time it takes (between 5 & 6 seconds)
- 1.3Mo does not seem a lot to fit in RAM, the network speed is far more than 10Mbit/s.

Kibana launches the query on a local client node, which does not show any logs.

Is there some parameter I missed ? Where could I troubleshoot this issue ?

Thank you,  
Regards,  
Grégoire

---

<div class="post-metadata">

**Author:** ![Retenodus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/retenodus/32/28063_2.png) [@Retenodus](https://discuss.elastic.co/u/Retenodus)\
**Post date:** [February 26, 2018, 9:26am UTC](https://discuss.elastic.co/t/discover-query-timeout-after-a-99h-treshold/121083/2 "2018-02-26T09:26:10Z")

</div>

Hello,

Is there someone who knows what I could miss ? Outside of CPU, RAM, IO, where could be the bottleneck ?

Regards,  
Grégoire

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 28, 2018, 5:25am UTC](https://discuss.elastic.co/t/discover-query-timeout-after-a-99h-treshold/121083/3 "2018-02-28T05:25:50Z")

</div>

What is the average size of your documents? Are you using the default value for `discover:sampleSize` under `Advanced Settings`? Have you tried setting `doc_table:highlight` to `false` under `Advanced Settings` to see if t his makes a difference?

---

<div class="post-metadata">

**Author:** ![Retenodus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/retenodus/32/28063_2.png) [@Retenodus](https://discuss.elastic.co/u/Retenodus)\
**Post date:** [March 7, 2018, 7:17pm UTC](https://discuss.elastic.co/t/discover-query-timeout-after-a-99h-treshold/121083/4 "2018-03-07T19:17:47Z")

</div>

The average size of documents is ~700 bytes. I kept the defaut value for discover:sampleSize, and indeed, disabling highlight enable me to get more data. Now, I still have performances issues but it does not seem to be a kibana one.

Is there some documentation to estimate the impact of highlight and plan how to size my kibana instances ?

Thank you,  
Regards,  
Grégoire

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2018, 7:18pm UTC](https://discuss.elastic.co/t/discover-query-timeout-after-a-99h-treshold/121083/5 "2018-04-04T19:18:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
