# \_field\_caps API takes long time (more than a minute) to return results causing kibana to not be able to refresh index pattern

**URL:** <https://discuss.elastic.co/t/field-caps-api-takes-long-time-more-than-a-minute-to-return-results-causing-kibana-to-not-be-able-to-refresh-index-pattern/198933>\
**Category:** Elasticsearch\
**Created:** [September 10, 2019, 4:21pm UTC](https://discuss.elastic.co/t/field-caps-api-takes-long-time-more-than-a-minute-to-return-results-causing-kibana-to-not-be-able-to-refresh-index-pattern/198933 "2019-09-10T16:21:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![nikhil-bhat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil-bhat/32/53939_2.png) [@nikhil-bhat](https://discuss.elastic.co/u/nikhil-bhat)\
**Post date:** [September 10, 2019, 4:21pm UTC](https://discuss.elastic.co/t/field-caps-api-takes-long-time-more-than-a-minute-to-return-results-causing-kibana-to-not-be-able-to-refresh-index-pattern/198933/1 "2019-09-10T16:21:05Z")

</div>

**Elasticsearch version** 6.7.2

**JVM version** Java HotSpot(TM) 64-Bit Server VM (1.8.0\_172):

**OS version** Linux

**field\_caps API takes long time (more than a minute) to return results** :

**Steps to reproduce** :  
1.) Index pattern with about 409 matching indices with about 61 fields  
2.) curl -XGET [https://esurl:9200/indexpattern-](https://esurl:9200/indexpattern-)_/\_field\_caps?fields=_  
2.) Takes 1 minute 45 seconds to get the result.

This causes kibana to not be able to refresh the index pattern as default timeout is set to 30 seconds.  
Is it on expected lines , Anything that can be done to speed up this api ?. Cluster is not resource constrained?

I found a similar issue [Kibana index is unresponsive](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575)  
with responses by @chrisronline

---

<div class="post-metadata">

**Author:** ![dliappis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dliappis/32/56174_2.png) [@dliappis](https://discuss.elastic.co/u/dliappis)\
**Post date:** [September 13, 2019, 2:55pm UTC](https://discuss.elastic.co/t/field-caps-api-takes-long-time-more-than-a-minute-to-return-results-causing-kibana-to-not-be-able-to-refresh-index-pattern/198933/2 "2019-09-13T14:55:39Z")

</div>

Hi @nikhil-bhat,

To get a ball bark idea of the impact, I attempted to run `GET _field_caps?fields=*` -- which should be rather expensive -- on a moderate 6.7 cloud cluster with 268 indices, most of them generated by metricbeat with 1342 fields, and the response took about 1s.

Are you certain that your cluster is not under pressure?

Rgs,  
Dimitris

---

<div class="post-metadata">

**Author:** ![nikhil-bhat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil-bhat/32/53939_2.png) [@nikhil-bhat](https://discuss.elastic.co/u/nikhil-bhat)\
**Post date:** [September 16, 2019, 3:34pm UTC](https://discuss.elastic.co/t/field-caps-api-takes-long-time-more-than-a-minute-to-return-results-causing-kibana-to-not-be-able-to-refresh-index-pattern/198933/3 "2019-09-16T15:34:41Z")

</div>

hi @dliappis hope you are having a pleasant day .  
the cluster in question is not under any load .

the field caps api still took above 1minute for the index pattern(415 indices) with 71 fields .  
should i attach node stats and any other detail for emphasis.  
All of the indices are of size less than 30 mb .

---

<div class="post-metadata">

**Author:** ![dliappis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dliappis/32/56174_2.png) [@dliappis](https://discuss.elastic.co/u/dliappis)\
**Post date:** [September 16, 2019, 4:07pm UTC](https://discuss.elastic.co/t/field-caps-api-takes-long-time-more-than-a-minute-to-return-results-causing-kibana-to-not-be-able-to-refresh-index-pattern/198933/4 "2019-09-16T16:07:01Z")

</div>

Hey @nikhil-bhat,

Could you collect the output from the [hot\_threads API](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-nodes-hot-threads.html) during the execution of your field caps query and paste here the top entries? Please take care that you mask any private data, such as public IP addresses, before posting here.

Dimitris

---

<div class="post-metadata">

**Author:** ![nikhil-bhat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil-bhat/32/53939_2.png) [@nikhil-bhat](https://discuss.elastic.co/u/nikhil-bhat)\
**Post date:** [September 25, 2019, 9:24am UTC](https://discuss.elastic.co/t/field-caps-api-takes-long-time-more-than-a-minute-to-return-results-causing-kibana-to-not-be-able-to-refresh-index-pattern/198933/5 "2019-09-25T09:24:45Z")

</div>

here are the links to hot thread api output after i hit refresh on index pattern in kibana

HIT 1

> <https://gist.github.com/nikhil-bhat/b86983baab49cf6fd19732c82a951b33>

HIT 2

> <https://gist.github.com/nikhil-bhat/8e519502599d3ebced308e5f744294de>

---

<div class="post-metadata">

**Author:** ![dliappis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dliappis/32/56174_2.png) [@dliappis](https://discuss.elastic.co/u/dliappis)\
**Post date:** [September 30, 2019, 4:44pm UTC](https://discuss.elastic.co/t/field-caps-api-takes-long-time-more-than-a-minute-to-return-results-causing-kibana-to-not-be-able-to-refresh-index-pattern/198933/6 "2019-09-30T16:44:13Z")

</div>

Hello @nikhil-bhat,

Looking at your hot threads output first of all we can see that some of your data nodes (data-04/08/03/01) are heavily occupied in indexing.

A number of the thread dumps from data nodes though (data-01/data-05) show that SearchGuard is installed and it seems to spend most of the time resolving index patterns while `TransportFieldCapabilitiesAction` is being called.

Since SearchGuard is a third party plugin we can’t really advise any further about what’s going on here. If the performance issue can be reproduced with Search Guard disabled or when using the [free security features](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/security-settings.html) from Elastic [included in 6.8+](https://www.elastic.co/blog/security-for-elasticsearch-is-now-free), we're happy to continue investigating.

Regards,  
Dimitris

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2019, 4:51pm UTC](https://discuss.elastic.co/t/field-caps-api-takes-long-time-more-than-a-minute-to-return-results-causing-kibana-to-not-be-able-to-refresh-index-pattern/198933/7 "2019-10-28T16:51:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
