# How to tune up search performance?

**URL:** <https://discuss.elastic.co/t/how-to-tune-up-search-performance/198179>\
**Category:** Elasticsearch\
**Created:** [September 5, 2019, 7:16am UTC](https://discuss.elastic.co/t/how-to-tune-up-search-performance/198179 "2019-09-05T07:16:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ted\_ye](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@ted\_ye](https://discuss.elastic.co/u/ted_ye)\
**Post date:** [September 5, 2019, 7:16am UTC](https://discuss.elastic.co/t/how-to-tune-up-search-performance/198179/1 "2019-09-05T07:16:03Z")

</div>

hello every experts:  
I want to ask for how to tune up search performance?  
My cluster:  
3 \* Master-eligible nodes with 2 cores 4G RAM  
3 \* coordinating nodes with 2 cores 8G RAM  
5 \* data nodes with 8cores 32G RAM  
elasticsearch version : 7.0.1  
there are 0.2 billion logs per day.  
And I search all logs of today on kibana, about 0.12 billion items,it takes 20 seconds to return!  
!  
[image|690x182](https://discuss.elastic.co/uploads/short-url/397Do3cK4AJ1quhyCQxTx1rz2GT.png)  
How can I tune up the search speed? Thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 5, 2019, 8:13am UTC](https://discuss.elastic.co/t/how-to-tune-up-search-performance/198179/2 "2019-09-05T08:13:09Z")

</div>

Have you identified what is limiting performance? Are you saturating CPU? Are you limited by disk utilisation? How large are your indices and shards?

---

<div class="post-metadata">

**Author:** ![ted\_ye](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@ted\_ye](https://discuss.elastic.co/u/ted_ye)\
**Post date:** [September 5, 2019, 8:37am UTC](https://discuss.elastic.co/t/how-to-tune-up-search-performance/198179/3 "2019-09-05T08:37:29Z")

</div>

I‘ve done nothing to limit the performence.I set each data node jvm RAM with 15G.  
I index the logs by date. Everyday has a index , every index has 5 shards and 0 replica,each shard locates on each data node. I set the index sort on timestamp. Is this has any problem?  
here is today's index setting:  
{  
"xxx-xxx-log-2019.09.05" : {  
"settings" : {  
"index" : {  
"lifecycle" : {  
"name" : "xxx-log-keep-15days"  
},  
"refresh\_interval" : "5s",  
"number\_of\_shards" : "5",  
"provided\_name" : "xxx-xxx-log-2019.09.05",  
"merge" : {  
"scheduler" : {  
"max\_thread\_count" : "1"  
}  
},  
"creation\_date" : "1567612807191",  
"sort" : {  
"field" : "@timestamp"  
},  
"number\_of\_replicas" : "0",  
"uuid" : "vsewVpzgQsaOfXICv8TwEw",  
"version" : {  
"created" : "7000199"  
}  
}  
}  
}  
}  
here is the kibana query :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1c963ac7deb3781750a372e917b6832cbfc0171f.png)

---

<div class="post-metadata">

**Author:** ![ted\_ye](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@ted\_ye](https://discuss.elastic.co/u/ted_ye)\
**Post date:** [September 6, 2019, 3:47am UTC](https://discuss.elastic.co/t/how-to-tune-up-search-performance/198179/4 "2019-09-06T03:47:16Z")

</div>

I used the search profile to check this problem. I use the kibana to search the last 15 minutes logs, search request is :  
{  
"version": true,  
"size": 500,  
"sort": [  
{  
"@timestamp": {  
"order": "desc",  
"unmapped\_type": "boolean"  
}  
}  
],  
"\_source": {  
"excludes":   
},  
"aggs": {  
"2": {  
"date\_histogram": {  
"field": "@timestamp",  
"interval": "30s",  
"time\_zone": "Asia/Shanghai",  
"min\_doc\_count": 1  
}  
}  
},  
"stored\_fields": [  
"_"  
],  
"script\_fields": {},  
"docvalue\_fields": [  
{  
"field": "@timestamp",  
"format": "date\_time"  
}  
],  
"query": {  
"bool": {  
"must": [  
{  
"range": {  
"@timestamp": {  
"format": "strict\_date\_optional\_time",  
"gte": "2019-09-06T03:21:30.108Z",  
"lte": "2019-09-06T03:36:30.108Z"  
}  
}  
}  
],  
"filter": [  
{  
"match\_all": {}  
}  
],  
"should": [],  
"must\_not": []  
}  
},  
"highlight": {  
"pre\_tags": [  
"@kibana-highlighted-field@"  
],  
"post\_tags": [  
"@/kibana-highlighted-field@"  
],  
"fields": {  
"_": {}  
},  
"fragment\_size": 2147483647  
}  
}

and the profile is :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/8/b8ffc37241e7eeac76e38633429b41a3473450cf.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7ca4ab5640acc2cc3c92ae563f5c5cef0637044b.png)  
the next\_doc cost more time, how to make it better?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2019, 3:47am UTC](https://discuss.elastic.co/t/how-to-tune-up-search-performance/198179/5 "2019-10-04T03:47:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
