# Elasticsearch index heavy reads

**URL:** <https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739>\
**Category:** Elasticsearch\
**Created:** [March 15, 2023, 9:10am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739 "2023-03-15T09:10:51Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![hopa56](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Post date:** [March 15, 2023, 9:10am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/1 "2023-03-15T09:10:51Z")

</div>

i have 3 indices in the cluster that are read-heavy and the load on the nodes on which the shards of these indices are located is very high (the indexes are small, the largest index weighs 5 gigabytes)  
we are thinking to provision a separate cluster for them

what do you do in such cases? or is it better to add more nodes to the existing cluster and label them as hot (sorry, not strong in elastic terminology) and schedule these indexes on them  
but I see only 1 plus for this approach (do not provision additional cluster), but for the rest, the load will still go to the control plane (the same masters, all sorts of coordinator and ingest nodes)  
It seems to me that it's still easier to provision separate cluster, or am I wrong?  
Thanks in advance to everyone for the replies!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 20, 2023, 6:40am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/2 "2023-03-20T06:40:52Z")

</div>

Welcome to our community! 😃

How big are your nodes in terms of hardware?

---

<div class="post-metadata">

**Author:** ![hopa56](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Post date:** [March 20, 2023, 6:44am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/3 "2023-03-20T06:44:27Z")

</div>

Thank you!  
my nodes are  
16 vCPU  
16 GB ram ( 8 gb heap )  
( i have 4 data only node and 1 master node )

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 20, 2023, 7:26am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/4 "2023-03-20T07:26:03Z")

</div>

> [@hopa56](#):
>
> ( i have 4 data only node and 1 master node )

That is not ideal, you have no redundancy if you lose that master node and your cluster will be unavailable.

Otherwise if your index is small and you have decent hardware support, we might need more info on why you think you have heavy read loads. Things like mappings, queries, query rates, logs etc.

---

<div class="post-metadata">

**Author:** ![hopa56](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Post date:** [March 28, 2023, 4:35am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/5 "2023-03-28T04:35:41Z")

</div>

@warkolm Sorry i have 2 another master eligble nodes, but 5 node is only master node

this index is used for GET user profile, and at the end of month ( when users get notification about bonuses ) almost all users login into application

and hot\_threads shows that this index is under heavy load at this times

---

<div class="post-metadata">

**Author:** ![hopa56](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Post date:** [March 31, 2023, 6:19am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/6 "2023-03-31T06:19:21Z")

</div>

😀 any ideas? thank you

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [March 31, 2023, 10:32am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/7 "2023-03-31T10:32:45Z")

</div>

> [@hopa56](#):
>
> It seems to me that it's still easier to provision separate cluster, or am I wrong?

It's certainly much easier to manage one cluster, and I don't think it makes much difference in terms of performance because ...

> [@hopa56](#):
>
> the load will still go to the control plane (the same masters, all sorts of coordinator and ingest nodes)

... this reasoning is unsound. Master nodes and ingest nodes are not involved in searches, and you can scale searches horizontally a _very_ long way within a single cluster.

---

<div class="post-metadata">

**Author:** ![hopa56](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Post date:** [March 31, 2023, 11:08am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/8 "2023-03-31T11:08:52Z")

</div>

@DavidTurner  
Okay, so for example i have cluster of 5 nodes, and 1 index that has very intensive reads, so it can slow down all other indexes ( in terms of using Harware ) so i need to label this node as hot and migrate all shards to this nodes right?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [March 31, 2023, 12:04pm UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/9 "2023-03-31T12:04:15Z")

</div>

I would expect scaling _in_ to a single node would make things run a bunch slower. Surely you want to scale _out_?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 31, 2023, 12:06pm UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/10 "2023-03-31T12:06:27Z")

</div>

How many primary and replica shards do these read intensive indices have?

How much data in total does each node hold?

---

<div class="post-metadata">

**Author:** ![hopa56](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Post date:** [April 3, 2023, 2:14am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/11 "2023-04-03T02:14:46Z")

</div>

for now i have 1 primary and 1 replica shards  
in cluster i have about 150gb of all data, in read intensive indices i have 20gb @Christian_Dahlqvist

---

<div class="post-metadata">

**Author:** ![hopa56](https://avatars.discourse-cdn.com/v4/letter/h/bbe5ce/32.png) [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Post date:** [April 12, 2023, 4:20am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/12 "2023-04-12T04:20:42Z")

</div>

any ideas? thank you in advance!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 13, 2023, 6:55am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/13 "2023-04-13T06:55:56Z")

</div>

The best way to support very high read or search rates against an index (or set of indices) is to ensure there is enough operating system page cache space to hold them in memory and avoid disk I/O when they are under heavy load. I would recommend having a single primary and a single replica shard for these read-heavy indices. This should allow them to largely fit into the page cache across your nodes. It may also be worthwhile looking into trimming you heap size if you have headroom there and thereby give more memory to the OS page cache.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2023, 6:56am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739/14 "2023-05-11T06:56:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
