# Instant Aggregations

**URL:** <https://discuss.elastic.co/t/instant-aggregations/73498>\
**Category:** Elasticsearch\
**Created:** [February 1, 2017, 10:28am UTC](https://discuss.elastic.co/t/instant-aggregations/73498 "2017-02-01T10:28:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gleroy](https://avatars.discourse-cdn.com/v4/letter/g/3e96dc/32.png) [@gleroy](https://discuss.elastic.co/u/gleroy)\
**Post date:** [February 1, 2017, 10:28am UTC](https://discuss.elastic.co/t/instant-aggregations/73498/1 "2017-02-01T10:28:22Z")

</div>

Hello,

I recently upgraded to Elasticsearch 5.1.2 and I was eager to see the instant aggregations in action. I have a Kibana dashboard I refresh every 10s.

I expected the first request to take me between 1 and 2s, and the next ones a few dozens of ms, thanks to the request\_cache as described in [https://www.elastic.co/blog/instant-aggregations-rewriting-queries-for-fun-and-profit](https://www.elastic.co/blog/instant-aggregations-rewriting-queries-for-fun-and-profit)

However, it's not what happens, all queries take between 1 and 2s.

According to the documentation, the request\_cache is enabled by default for the indice and I don't override it for the request.

I indeed see that the request\_cache is populated but I see a lot of miss :

```
curl -XGET 'localhost:9201/logstash_myindice-v1-2017.02.01/_stats/request_cache?pretty'
{
  "_shards" : {
    "total" : 12,
    "successful" : 12,
    "failed" : 0
  },
  "_all" : {
    "primaries" : {
      "request_cache" : {
        "memory_size_in_bytes" : 77417,
        "evictions" : 0,
        "hit_count" : 254,
        "miss_count" : 710
      }
    },
    "total" : {
      "request_cache" : {
        "memory_size_in_bytes" : 413087,
        "evictions" : 0,
        "hit_count" : 507,
        "miss_count" : 1557
      }
    }
  },
  "indices" : {
    "logstash_myindice_v1-2017.02.01" : {
      "primaries" : {
        "request_cache" : {
          "memory_size_in_bytes" : 77417,
          "evictions" : 0,
          "hit_count" : 254,
          "miss_count" : 710
        }
      },
      "total" : {
        "request_cache" : {
          "memory_size_in_bytes" : 413087,
          "evictions" : 0,
          "hit_count" : 507,
          "miss_count" : 1557
        }
      }
    }
  }
}

```

Did I miss something ?

An example of kibana generated request:

```
{
  "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "query": "*",
            "analyze_wildcard": true
          }
        },
        {
          "query_string": {
            "analyze_wildcard": true,
            "query": "netflow.direction:0"
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": 1485928995494,
              "lte": 1485943395494,
              "format": "epoch_millis"
            }
          }
        }
      ],
      "must_not": []
    }
  },
  "size": 0,
  "_source": {
    "excludes": []
  },
  "aggs": {
    "2": {
      "date_histogram": {
        "field": "@timestamp",
        "interval": "5m",
        "time_zone": "Europe/Berlin",
        "min_doc_count": 1
      },
      "aggs": {
        "1": {
          "sum": {
            "field": "netflow.in_bytes"
          }
        }
      }
    }
  }
}

```

Is there an issue with the size of the cache, or rather with the request which can't take advantage of the instant aggregation ?

Regards,  
Grégoire

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 1, 2017, 11:20am UTC](https://discuss.elastic.co/t/instant-aggregations/73498/2 "2017-02-01T11:20:22Z")

</div>

The rewriting of queries in order to better utilise the cache applies to indices that are entirely within the time period and have not been updated (see the colourful images at the end of the blog post you linked to). The indices at the end of the interval will not be able to cache. How many indices do your query cover? How many of these are entirely within the time interval and are not being updated/modified?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2017, 11:20am UTC](https://discuss.elastic.co/t/instant-aggregations/73498/3 "2017-03-01T11:20:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
