# Elastic Tuning

**URL:** <https://discuss.elastic.co/t/elastic-tuning/167245>\
**Category:** Elasticsearch\
**Created:** [February 6, 2019, 9:16am UTC](https://discuss.elastic.co/t/elastic-tuning/167245 "2019-02-06T09:16:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![fedwe](https://avatars.discourse-cdn.com/v4/letter/f/a88e4f/32.png) [@fedwe](https://discuss.elastic.co/u/fedwe)\
**Post date:** [February 6, 2019, 9:16am UTC](https://discuss.elastic.co/t/elastic-tuning/167245/1 "2019-02-06T09:16:33Z")

</div>

Hello Elastic Team,

I am new in elastic search and i want to ask ,

I have 3 servers with 16 gb ram and virtual storage and 4 CPUs on each which is intel xeon E5-2699 v4 2.2 ghz 4 cores on each.

okay so i want to index documents through logstash and if you can tell me the instructions i can do to tune logstash and elasticsearch. My document is a csv file with about 150 columns of size 8gb. IT took 3 days to index it which is a really poor performance since this file is received every hour. I have all settings on default nothing touched in elastic configuration or logstash. Can you tell me if i need more servers and what type of nodes should i assign to each server and what to configure each server on logstash and elastic because i need maximum index performance. Thank you.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 6, 2019, 9:34am UTC](https://discuss.elastic.co/t/elastic-tuning/167245/2 "2019-02-06T09:34:36Z")

</div>

Make sure you have followed these [tuning guidelines for indexing](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/tune-for-indexing-speed.html) for Elasticsearch. Also make sure you have [optimised your mappings](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/tune-for-disk-usage.html) so you reduce the amount of unnecessary work.

When it comes to Logstash you should have a look at [these guidelines](https://www.elastic.co/guide/en/logstash/current/performance-tuning.html). As you are parsing large CSV files, it is worth noting that [the dissect filter can be significantly faster than the csv and/or grok filters](https://www.elastic.co/blog/logstash-dude-wheres-my-chainsaw-i-need-to-dissect-my-logs).

It is also worth having a look at the cluster while you are indexing to try and see what resource is limiting performance. For high indexing rates it is often CPU, network or disk performance (since you are using virtual storage I would recommend looking at disk I/O and iowait).

---

<div class="post-metadata">

**Author:** ![fedwe](https://avatars.discourse-cdn.com/v4/letter/f/a88e4f/32.png) [@fedwe](https://discuss.elastic.co/u/fedwe)\
**Post date:** [February 6, 2019, 9:54am UTC](https://discuss.elastic.co/t/elastic-tuning/167245/3 "2019-02-06T09:54:21Z")

</div>

okay and what can i do if i have poor i/o and disk rate

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 6, 2019, 9:59am UTC](https://discuss.elastic.co/t/elastic-tuning/167245/4 "2019-02-06T09:59:11Z")

</div>

Get faster storage or scale out the cluster (unless storage is likely to still be the bottleneck).

---

<div class="post-metadata">

**Author:** ![Abhilash\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhilash_b/32/40270_2.png) [@Abhilash\_B](https://discuss.elastic.co/u/Abhilash_B)\
**Post date:** [February 6, 2019, 10:04am UTC](https://discuss.elastic.co/t/elastic-tuning/167245/5 "2019-02-06T10:04:25Z")

</div>

Use SSDs. If you are already using it, see what's the output of `iostat`.

---

<div class="post-metadata">

**Author:** ![fedwe](https://avatars.discourse-cdn.com/v4/letter/f/a88e4f/32.png) [@fedwe](https://discuss.elastic.co/u/fedwe)\
**Post date:** [February 6, 2019, 11:29am UTC](https://discuss.elastic.co/t/elastic-tuning/167245/6 "2019-02-06T11:29:37Z")

</div>

this is my io ![io](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7ad55f12b94cb244060e3b8f4e1cca4314f32872.png) this is it and how can i scale out the cluster?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2019, 11:35am UTC](https://discuss.elastic.co/t/elastic-tuning/167245/7 "2019-03-06T11:35:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
