# Elasticsearch indexing slow

**URL:** <https://discuss.elastic.co/t/elasticsearch-indexing-slow/86988>\
**Category:** Elasticsearch\
**Created:** [May 24, 2017, 1:53pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-slow/86988 "2017-05-24T13:53:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kicker83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kicker83/32/121202_2.png) [@Kicker83](https://discuss.elastic.co/u/Kicker83)\
**Post date:** [May 24, 2017, 1:53pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-slow/86988/1 "2017-05-24T13:53:29Z")

</div>

Hi everyone!

I have a server with logstash, elasticsearch and kibana, and my index rating is about 4,500/s (107.4m documents in about 14 hours)

The problem is I'm having a lot of delay between the syslogs events and the elasticsearch indexed event. The delay is about two hours.

I'm indexing bluecoat logs, and I'm parsing the logs in logstash with grok and csv.

The server has 12 CPU with 32 GB of RAM. The storage is NFS, and I think that could be the problem, but I don't know how to see, if thats the problem certainly.

Another important detail, is in XPack monitoring I can see the traffic graphs with blank spaces, I mean, it seems elasticsearch stops indexing for one second.

How could I troubleshoot this problem? Is there any tunning option to configure in elasticsearch? (I disabled replicas and I change the refresh\_interval to 10s)

Thanks in advance!  
Regards

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 24, 2017, 4:20pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-slow/86988/2 "2017-05-24T16:20:58Z")

</div>

This is a single server? Not a clustered Elasticsearch? A single node can do a lot, but that might be part of the slowdown.

> [@Kicker83](#):
>
> The storage is NFS, and I think that could be the problem,

This is _not_ recommended. In fact, do not ever do this. See our storage recommendations [here](https://www.elastic.co/guide/en/elasticsearch/guide/2.x/indexing-performance.html#_storage).

> [@Kicker83](#):
>
> I can see the traffic graphs with blank spaces, I mean, it seems elasticsearch stops indexing for one second.

This could be any of a few things.

- Garbage collection in the JVM causes a pause in indexing
- Segment merges cause a pause in indexing (because you only have one node)
- Storage delays due to NFS (lock files and the like)
- Yet other possibilities.

These are most likely, though. Your best bet to get to real-time indexing is to have more nodes in your Elasticsearch cluster with local SSD storage.

---

<div class="post-metadata">

**Author:** ![Kicker83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kicker83/32/121202_2.png) [@Kicker83](https://discuss.elastic.co/u/Kicker83)\
**Post date:** [May 24, 2017, 5:51pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-slow/86988/3 "2017-05-24T17:51:16Z")

</div>

@theuntergeek Thanks so much for the info! I'll try to install another elasticsearch node (If someone gives me one server 😛). I'm afraid NFS is the only way I have to storage all data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2017, 5:51pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-slow/86988/4 "2017-06-21T17:51:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
