# Elastic search indexing tuninig

**URL:** <https://discuss.elastic.co/t/elastic-search-indexing-tuninig/166008>\
**Category:** Elasticsearch\
**Created:** [January 28, 2019, 2:38pm UTC](https://discuss.elastic.co/t/elastic-search-indexing-tuninig/166008 "2019-01-28T14:38:51Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![fadihaddad](https://avatars.discourse-cdn.com/v4/letter/f/4bbf92/32.png) [@fadihaddad](https://discuss.elastic.co/u/fadihaddad)\
**Post date:** [January 28, 2019, 2:38pm UTC](https://discuss.elastic.co/t/elastic-search-indexing-tuninig/166008/1 "2019-01-28T14:38:52Z")

</div>

Hello I have a server with 4 cpus each cpu has 4 cores and 16gb ram and a virtual storage.  
I tried to indexed a 250mb file but it took 30mins. How can we tune elastic search to the max to make it use all cpu cores and jvm and to index as fast as possible

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 28, 2019, 3:18pm UTC](https://discuss.elastic.co/t/elastic-search-indexing-tuninig/166008/2 "2019-01-28T15:18:08Z")

</div>

How did you go about indexing it? What did CPU usage and disk I/o stats and iowait look like while you were indexing? Have you followed [these guidelines](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/tune-for-indexing-speed.html)?

---

<div class="post-metadata">

**Author:** ![fadihaddad](https://avatars.discourse-cdn.com/v4/letter/f/4bbf92/32.png) [@fadihaddad](https://discuss.elastic.co/u/fadihaddad)\
**Post date:** [January 28, 2019, 10:19pm UTC](https://discuss.elastic.co/t/elastic-search-indexing-tuninig/166008/3 "2019-01-28T22:19:55Z")

</div>

Well i am new to elasticsearch and i need help t  
To understand more these guidelines. And how can i increase the numbers of threads to take maximum cpu capacity and use multiple cpus for indexing

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 28, 2019, 11:08pm UTC](https://discuss.elastic.co/t/elastic-search-indexing-tuninig/166008/4 "2019-01-28T23:08:26Z")

</div>

It's unclear to me what you are indexing (the content of your file) and how (which tool, code... you are using).

---

<div class="post-metadata">

**Author:** ![fadihaddad](https://avatars.discourse-cdn.com/v4/letter/f/4bbf92/32.png) [@fadihaddad](https://discuss.elastic.co/u/fadihaddad)\
**Post date:** [January 29, 2019, 7:07am UTC](https://discuss.elastic.co/t/elastic-search-indexing-tuninig/166008/5 "2019-01-29T07:07:58Z")

</div>

I am indexing through logstash because they are csv files and I this is the logstash conf file `input {  
file {  
path =\> "C:/Users/Fadi/Desktop/internship/OCC\*.csv"  
start\_position =\> "beginning"

}  
}  
filter {  
csv {  
separator =\> ","  
columns =\>  
["calltype", "recordtype", "chrononumber", "servedSubscriptionIDNumber", "servedSubscriptionID", "callingcallednumber", "callforwardflag", "callnumberincaseofCF", "calldate", "calltime", "faxdatavoicesms", "teleservicenumber", "number", "imsi", "intermediatecalltype", "inServicekey", "scfaddress", "mSCAddress", "totaloctet", "cdrType", "accountValueBefore", "accountValueAfter", "familyAndFriendsIndicator", "selectedCommunityID", "familyAndFriendsNo", "accountGroupID", "selectionTreeType", "servedAccount", "serviceOfferings", "terminationCause", "chargingContextID", "serviceContextID", "serviceSessionID", "resultCode", "resultCodeExtension", "triggerTime", "nodeName", "partialSequenceNumber", "lastPartialOutput", "correlationIDType", "correlationID", "servingElementType", "servingElement", "usedUnchargedServiceUnitsNumber", "usedUnchargedServiceUnits", "uCounternumber", "uCounter", "mAinbefore", "mAinafter", "mAincharge", "accessPoint", "sgsnaddress", "lastSgsnAddress", "ggsnaddress", "firstGgsnName", "lastGgsnAddress", "lastGgsnName", "imei", "dANumber", "dAList", "pamServiceID", "pamClassID", "scheduleID", "decimals", "currency", "currentPamPeriod", "allpartials", "chargeID", "aCCNumber", "aCCList", "bonusAccNumber", "bonusAccList", "bonusmAinBefore", "bonusmAinAfter", "bonusmAinChange", "bonusDANumber", "bonusDAList", "duration", "nCR", "sPI", "dASharedNumber", "dASharedList", "accumulatedCost", "providerAccount", "providerServiceClassID", "accountGroupID1", "accountValueDeducted", "accumulatedUnits", "accountUnitsDeducted", "treeparameterID", "treeparameterValue", "usedoffers", "sharedOfferID", "sharedFamilyAndfriendsID", "sharedFamilyAndfriendsNO", "providersfamilyandfriendsid", "sharedPamServiceID", "sharedPamClassID", "sharedScheduleID", "sharedCurrentPamPeriod", "sharedOfferProviderID", "uCSharedNumber", "uCSharedList", "treeparameterID1", "treeparameterValue1", "tDFNumber", "tDFList", "offerNumber", "offerList", "firstCellID", "lastCellID", "firstLAC", "lastLAC", "firstTAC", "lastTAC", "firstRATtype", "lastRATtype", "DA40,", "BONUSDA9"]

```
}

```

ruby {  
code =\> "  
x = event.get('dAList').split('|').collect { |t|  
c = t.split '~'  
{  
'DA\_ID' =\> c[0].to\_i,  
'DA\_Before' =\> c[1].to\_i,-  
'DA\_After' =\> c[2].to\_i,  
'DA\_Change' =\> c[3].to\_i,  
'DA\_ExpDate' =\> c[4]  
}  
}  
event.set('DAList', x)

"  
}

date {  
match =\> ["[DAList][0][DA\_ExpDate]", "YYYYMMdd", "YYYYMdd" , "YYYYMMd", "YYYYMd"]  
target =\> "[DAList][0][DA\_ExpDate]"  
timezone =\> "UTC"  
}  
date {  
match =\> ["[DAList][1][DA\_ExpDate]","YYYYMMdd", "YYYYMdd" , "YYYYMMd", "YYYYMd"]  
target =\> "[DAList][1][DA\_ExpDate]"  
timezone =\> "UTC"  
}  
date {  
match =\> ["[DAList][2][DA\_ExpDate]", "YYYYMMdd", "YYYYMdd" , "YYYYMMd", "YYYYMd" ]  
target =\> "[DAList][2][DA\_ExpDate]"  
timezone =\> "UTC"  
}  
date {  
match =\> ["[DAList][3][DA\_ExpDate]", "YYYYMMdd", "YYYYMdd" , "YYYYMMd", "YYYYMd" ]  
target =\> "[DAList][3][DA\_ExpDate]"  
timezone =\> "UTC"  
}  
date {  
match =\> ["[DAList][4][DA\_ExpDate]", "YYYYMMdd", "YYYYMdd" , "YYYYMMd", "YYYYMd" ]  
target =\> "[DAList][4][DA\_ExpDate]"  
timezone =\> "UTC"  
}  
date {  
match =\> ["[DAList][5][DA\_ExpDate]", "YYYYMMdd", "YYYYMdd" , "YYYYMMd", "YYYYMd"]  
target =\> "[DAList][5][DA\_ExpDate]"  
timezone =\> "UTC"  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost"  
index =\> "occ"  
document\_type =\> "data"

}  
stdout {  
codec =\> rubydebug}  
}`

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 29, 2019, 7:13am UTC](https://discuss.elastic.co/t/elastic-search-indexing-tuninig/166008/6 "2019-01-29T07:13:17Z")

</div>

What does seem to be limiting performance?

Are you saturating CPU while indexing? If so, how much its used by Elasticsearch and Logstash respectively?

What does disk I/O look like? Do you have very slow storage that could limit throughput? Elasticsearch is often quite I/O intensive during indexing.

---

<div class="post-metadata">

**Author:** ![fadihaddad](https://avatars.discourse-cdn.com/v4/letter/f/4bbf92/32.png) [@fadihaddad](https://discuss.elastic.co/u/fadihaddad)\
**Post date:** [January 29, 2019, 11:23am UTC](https://discuss.elastic.co/t/elastic-search-indexing-tuninig/166008/7 "2019-01-29T11:23:14Z")

</div>

I will set metric beat to view them I don't have it installed yet and I will reply the result but all I did was change the JVM heap and shards to 1 and all the left settings are default and I also have only elastic stack on my server

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2019, 11:23am UTC](https://discuss.elastic.co/t/elastic-search-indexing-tuninig/166008/8 "2019-02-26T11:23:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
