# Info on slowlog

**URL:** <https://discuss.elastic.co/t/info-on-slowlog/219948>\
**Category:** Elasticsearch\
**Created:** [February 19, 2020, 11:18am UTC](https://discuss.elastic.co/t/info-on-slowlog/219948 "2020-02-19T11:18:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dantonag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dantonag/32/44130_2.png) [@dantonag](https://discuss.elastic.co/u/dantonag)\
**Post date:** [February 19, 2020, 11:18am UTC](https://discuss.elastic.co/t/info-on-slowlog/219948/1 "2020-02-19T11:18:38Z")

</div>

Hello,  
we are on ES6.8 with a big cluster (many terabytes indexed per day), and sometimes the search thread pool fills up (currently the len is set to 1000).

We would like to know which queries are filling our search queue.  
I'm aware of "slowlog", but I would like to know:

1. how computationally intensive can slowlog be? How much CPU will it eat, in percentage?
2. are there alternatives to slowlog? commands or API I can use to find slow queries

Thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 19, 2020, 2:11pm UTC](https://discuss.elastic.co/t/info-on-slowlog/219948/2 "2020-02-19T14:11:12Z")

</div>

The slowlog mechanism is logging queries that exceed a manually configured threshold, it does not introduce some new heavy query mechanism, if you are afraid of that.

And it is the one key to find slow queries, there are no other. The other workaround I could imagine is to log the full query time from start to query being returned in your application, that will also include network traffic (which is a good thing to have a full overview).

---

<div class="post-metadata">

**Author:** ![dantonag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dantonag/32/44130_2.png) [@dantonag](https://discuss.elastic.co/u/dantonag)\
**Post date:** [February 21, 2020, 1:44pm UTC](https://discuss.elastic.co/t/info-on-slowlog/219948/3 "2020-02-21T13:44:58Z")

</div>

Thanks for your answer.  
We would also like to know **who** is the user that is running a certain slow query.  
We've found this parameter in the documentation (of audit):

xpack.security.audit.index.events.emit\_request\_body: true

but I would like to know if it's possible to enable query tracing only for slow queries (the above parameter seems to do it for every request).

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2020, 1:45pm UTC](https://discuss.elastic.co/t/info-on-slowlog/219948/4 "2020-03-20T13:45:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
