# Elasticsearch slow performance

**URL:** <https://discuss.elastic.co/t/elasticsearch-slow-performance/27099>\
**Category:** Elasticsearch\
**Created:** [August 10, 2015, 5:46am UTC](https://discuss.elastic.co/t/elasticsearch-slow-performance/27099 "2015-08-10T05:46:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksvagarwal](https://avatars.discourse-cdn.com/v4/letter/k/8baadc/32.png) [@ksvagarwal](https://discuss.elastic.co/u/ksvagarwal)\
**Post date:** [August 10, 2015, 5:46am UTC](https://discuss.elastic.co/t/elasticsearch-slow-performance/27099/1 "2015-08-10T05:46:30Z")

</div>

When I started parsing my logs with ELK stack, the speed was good but sometimes, I was able to parse 50000 logs in a minute and sometimes, it was as low as 4000 in a minute. I parsed about 2.5 million data in two and a half hours. After parsing this data, the ELK stack has slowed down.

I am now getting a speed of 1000 logs per 10 minutes. I don't understand what's wrong with it. My elasticsearch server has 64GB RAM with 31GB as memory heap. So it shouldn't give such bad performance! Please help me out here. Thanks in advance! 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 10, 2015, 6:18am UTC](https://discuss.elastic.co/t/elasticsearch-slow-performance/27099/2 "2015-08-10T06:18:45Z")

</div>

Unless you scale horizontally you will probably run into this, as there are only so many resources on a given single host.

How much data is that, in GB?

---

<div class="post-metadata">

**Author:** ![ksvagarwal](https://avatars.discourse-cdn.com/v4/letter/k/8baadc/32.png) [@ksvagarwal](https://discuss.elastic.co/u/ksvagarwal)\
**Post date:** [August 10, 2015, 6:35am UTC](https://discuss.elastic.co/t/elasticsearch-slow-performance/27099/3 "2015-08-10T06:35:00Z")

</div>

It's around 6 GB.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 10, 2015, 6:54am UTC](https://discuss.elastic.co/t/elasticsearch-slow-performance/27099/4 "2015-08-10T06:54:52Z")

</div>

That does sound odd.

What version (java and ES), how are you indexing (bulk or single, client or...?), how are you monitoring, have you checked the logs for GC?

---

<div class="post-metadata">

**Author:** ![ksvagarwal](https://avatars.discourse-cdn.com/v4/letter/k/8baadc/32.png) [@ksvagarwal](https://discuss.elastic.co/u/ksvagarwal)\
**Post date:** [August 10, 2015, 7:01am UTC](https://discuss.elastic.co/t/elasticsearch-slow-performance/27099/5 "2015-08-10T07:01:13Z")

</div>

Java 1.8 oracle stable and ES 1.5. Indexing via a single logstash server which picks data from redis. Architecture is like this:

```
logstash ---> redis ---> logstash ---> elasticsearch

```

I am not monitoring health of elasticsearch. I know that I need more data as currently I am load testing the architecture. And my numbers doesn't match with the ones from my previous parsing.

---

<div class="post-metadata">

**Author:** ![ksvagarwal](https://avatars.discourse-cdn.com/v4/letter/k/8baadc/32.png) [@ksvagarwal](https://discuss.elastic.co/u/ksvagarwal)\
**Post date:** [August 10, 2015, 9:13am UTC](https://discuss.elastic.co/t/elasticsearch-slow-performance/27099/6 "2015-08-10T09:13:22Z")

</div>

So I started monitoring my ES with Marvel and the status shown is yellow. So I guess that means that my shards are not replicated, but would that slow the elasticsearch this much?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 10, 2015, 10:50pm UTC](https://discuss.elastic.co/t/elasticsearch-slow-performance/27099/7 "2015-08-10T22:50:57Z")

</div>

No it wouldn't.

What sort of data is this, ie what is the structure?

---

<div class="post-metadata">

**Author:** ![ksvagarwal](https://avatars.discourse-cdn.com/v4/letter/k/8baadc/32.png) [@ksvagarwal](https://discuss.elastic.co/u/ksvagarwal)\
**Post date:** [August 11, 2015, 4:06pm UTC](https://discuss.elastic.co/t/elasticsearch-slow-performance/27099/8 "2015-08-11T16:06:00Z")

</div>

These are the nginx access logs. But I guess I have found the error. The logstash completely stops sending data when it encounters data in the form of encoded unicode characters. I am now trying to solve that. Any help on that front would be great! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:56pm UTC](https://discuss.elastic.co/t/elasticsearch-slow-performance/27099/9 "2017-07-05T23:56:27Z")

</div>


