# ES getting killed by heavy queries

**URL:** <https://discuss.elastic.co/t/es-getting-killed-by-heavy-queries/124142>\
**Category:** Elasticsearch\
**Created:** [March 15, 2018, 4:25pm UTC](https://discuss.elastic.co/t/es-getting-killed-by-heavy-queries/124142 "2018-03-15T16:25:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![zygisa](https://avatars.discourse-cdn.com/v4/letter/z/f05b48/32.png) [@zygisa](https://discuss.elastic.co/u/zygisa)\
**Post date:** [March 15, 2018, 4:25pm UTC](https://discuss.elastic.co/t/es-getting-killed-by-heavy-queries/124142/1 "2018-03-15T16:25:04Z")

</div>

Hey guys,

Recently we had a couple of situations where our ES cluster received an influx of heavy queries and that pretty much killed the cluster. CPU utilization reached 100% on all of the nodes in the cluster meanwhile heap/RAM was doing fine. We had a bunch of queries running for more than 300 seconds that we manually killed using task management API and cluster recovered. Obviously, this is not a preferable way of doing with this.

So the question is: is there any circuit breaker (or anything like that) that would kill long running heavy queries after a certain amount of time (or when CPU util reaches certain threshold)? We have circuit breakers to prevent OOM but there's nothing for the CPU utilization as far as I can tell after checking the documentation.

Thanks!

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [March 15, 2018, 5:40pm UTC](https://discuss.elastic.co/t/es-getting-killed-by-heavy-queries/124142/2 "2018-03-15T17:40:47Z")

</div>

See the search timeout option, which by default is unbounded: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-body.html#\_parameters\_4](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-body.html#_parameters_4)

---

<div class="post-metadata">

**Author:** ![zygisa](https://avatars.discourse-cdn.com/v4/letter/z/f05b48/32.png) [@zygisa](https://discuss.elastic.co/u/zygisa)\
**Post date:** [March 16, 2018, 7:57am UTC](https://discuss.elastic.co/t/es-getting-killed-by-heavy-queries/124142/3 "2018-03-16T07:57:31Z")

</div>

Is there a way to set the timeout on cluster side (config/API call) rather than the client side?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [March 16, 2018, 8:45am UTC](https://discuss.elastic.co/t/es-getting-killed-by-heavy-queries/124142/4 "2018-03-16T08:45:51Z")

</div>

Yep: [https://www.elastic.co/guide/en/elasticsearch/reference/6.2/search.html#global-search-timeout](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/search.html#global-search-timeout)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2018, 8:46am UTC](https://discuss.elastic.co/t/es-getting-killed-by-heavy-queries/124142/5 "2018-04-13T08:46:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
