# ELK for 30k eps - memory problem

**URL:** <https://discuss.elastic.co/t/elk-for-30k-eps-memory-problem/46695>\
**Category:** Elasticsearch\
**Created:** [April 7, 2016, 2:16pm UTC](https://discuss.elastic.co/t/elk-for-30k-eps-memory-problem/46695 "2016-04-07T14:16:10Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [April 7, 2016, 3:03pm UTC](https://discuss.elastic.co/t/elk-for-30k-eps-memory-problem/46695/2 "2016-04-07T15:03:54Z")

</div>

Hi em01,

By default, your version of elasticsearch is building fielddata every time you access the timestamp field for aggregation or sorting, which happens pretty much every time you open any kibana dashboard or execute a search query that sorts by timestamp. Because building fielddata is an expensive process, elasticsearch caches it in memory. Please see [https://www.elastic.co/guide/en/elasticsearch/guide/master/fielddata.html](https://www.elastic.co/guide/en/elasticsearch/guide/master/fielddata.html) and [https://www.elastic.co/guide/en/elasticsearch/guide/master/doc-values.html](https://www.elastic.co/guide/en/elasticsearch/guide/master/doc-values.html) for more informaiton.

So, to avoid this problem, you can either give more memory to your elasticsearch cluster by adding more nodes or you can switch to doc values for the timestamp field. See [Using Doc Values](https://discuss.elastic.co/t/using-doc-values/29066/2) for some pointers on how to enable doc values on the logstash level.

---

_[View the full topic](https://discuss.elastic.co/t/elk-for-30k-eps-memory-problem/46695)._
