# Elasticsearch cluster performance tuning

**URL:** <https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812>\
**Category:** Elasticsearch\
**Created:** [June 12, 2020, 5:23am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812 "2020-06-12T05:23:44Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [June 12, 2020, 5:23am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/1 "2020-06-12T05:23:44Z")

</div>

Hi,  
Following an error I got in Kibana and the following posts

> [@Kibana looks like it cancels requests if they take more than 30 seconds?](https://discuss.elastic.co/t/kibana-looks-like-it-cancels-requests-if-they-take-more-than-30-seconds/219689):
>
> I was running the newest version of Kibana, 7.6. I was noticing that during ingestion process, some of my visualizations are taking over 30 seconds. When they take that long it will expose the error: [esaggs] \> Unexpected token u in JSON at position 0 When looking at the network request, it says cancelled. I think that it auto-cancels requests but it seems that the timeout will occur around the 30 second mark. I have some visualizations for the last 2 days, pretty much monitoring the count…

> [@Issue after upgrading to 7.5.2 - SyntaxError: Unexpected token u in JSON at position 0 at JSON.parse (\<anonymous\>) at server.route.handler](https://discuss.elastic.co/t/issue-after-upgrading-to-7-5-2-syntaxerror-unexpected-token-u-in-json-at-position-0-at-json-parse-anonymous-at-server-route-handler/216623):
>
> Hello, Today we have performed an upgrate to Kiana 7.5.2 (ES at 7.5) and we have noticed an issue with one of our indices which was working fine. It seems like this particular index pattern is returning an error. Other seems to be working fine. { "type":"error", "@timestamp":"2020-01-27T08:58:44Z", "tags":[], "pid":23965, "level":"error", "error":{ "message":"Unexpected token u in JSON at position 0", "name":"SyntaxError", "stack":"SyntaxError: Unexp…

How can I optimise and tune the elastic cluster?

- Elasticsearch/Kibana version are 7.6.2
- I have 5 nodes in the cluster, all run on a CentOS 7 VMs
- 28G per node for JVM
- File swap is disabled on all nodes
- Using shards calculation according to [this article](https://thoughts.t37.net/designing-the-perfect-elasticsearch-cluster-the-almost-definitive-guide-e614eabc1a87).

Thanks!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 12, 2020, 6:25am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/2 "2020-06-12T06:25:53Z")

</div>

I have not seen the article you linked to before. How many indices and shards do you have? What is the average size?

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [June 15, 2020, 12:22am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/3 "2020-06-15T00:22:25Z")

</div>

Hi,  
Currently I have  
~ 700 indices  
~ 2240 shards  
~ 53GB Average size (primary+replica)

Thanks!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 15, 2020, 5:08am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/4 "2020-06-15T05:08:07Z")

</div>

What issues are you having? What is it you want to tune for?

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [June 15, 2020, 5:38am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/5 "2020-06-15T05:38:32Z")

</div>

Currently Kibana is hitting a timeout exception/error.  
In the first link I gave, the user named @flash1293, advises to

> Maybe it is possible to tune your server a bit without adding hardware. For guidance around this you can post in the [ES forum](https://discuss.elastic.co/c/elasticsearch/6) and I'm sure you will find help.

So I am trying to understand if there is any further optimisation I can do on the cluster?!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 15, 2020, 5:57am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/6 "2020-06-15T05:57:17Z")

</div>

The first thing to do is identify what is causing the timeouts.

If you look in the Elasticsearch logs, do you see indications of long and/or frequent GC? You have a lot of data on each node so it is possible that you are suffering from heap pressure.

What does CPU usage look like while you have queries timing out? Is any node saturated?

The last thing that commonly causes timeouts is issues around storage performance. Are you monitoring disk utilisation and iowait? What does disk usage look like during query timeouts?

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [June 15, 2020, 6:29am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/7 "2020-06-15T06:29:33Z")

</div>

Hi @Christian_Dahlqvist  
You have good questions. Unfortunately, I cannot answer them right now as I am not monitoring all those metrics. It will require some more time/effort.

In the short run, I am planning to monitor query times.  
In the longer run, I would sure want to monitor more metrics and understand what is affecting the performance.

Cheers

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [June 18, 2020, 6:05am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/8 "2020-06-18T06:05:51Z")

</div>

Hi @Christian_Dahlqvist  
Any recommendations regarding Monitor queries running time?  
What is the best way to do it?  
Cheers!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 18, 2020, 6:57am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/9 "2020-06-18T06:57:00Z")

</div>

Do you have Elasticsearch monitoring enabled?

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [June 24, 2020, 12:00am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/10 "2020-06-24T00:00:57Z")

</div>

What do you mean?  
Not sure how to answer.

Thanks!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 24, 2020, 3:35am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/11 "2020-06-24T03:35:50Z")

</div>

Have a look at [the docs around monitoring](https://www.elastic.co/guide/en/elasticsearch/reference/current/monitor-elasticsearch-cluster.html).

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [June 24, 2020, 3:54am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/12 "2020-06-24T03:54:14Z")

</div>

currently, monitoring with filebeat and metricbeat.  
[trying to configure packetbeat](https://discuss.elastic.co/t/exiting-data-path-already-locked-by-another-beat-packetbeat/238368) for query runtime.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2020, 3:54am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-performance-tuning/236812/13 "2020-07-22T03:54:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
