# Kibana is slow to respond

**URL:** <https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290>\
**Category:** Kibana\
**Created:** [March 24, 2016, 12:19am UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290 "2016-03-24T00:19:06Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![vilas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vilas/32/613_2.png) [@vilas](https://discuss.elastic.co/u/vilas)\
**Post date:** [March 24, 2016, 12:19am UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/1 "2016-03-24T00:19:06Z")

</div>

Hi,

We have elasticsearch 1.5.2 cluster with following distribution:  
Node1: Master+Data  
Node2: Master+Data  
Node3: Master+Data  
Node4: Data  
Node5: Data  
Node6: Client (For Kibana)  
Node7: Client

Node3, Node4, Node5 =\> On same physical node  
Node6, Node7 =\> One same physical node

Our ES is very slow (takes a minute or sometimes gets struck forever) and does not respond well when we retrieve data for last 15 days or more.  
We tried adding extra client node (Node 7), but it did not change any response time.

Need suggestions in improving performance. Can adding Client nodes and dedicated master nodes help?

Thanks.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [March 24, 2016, 2:25pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/2 "2016-03-24T14:25:42Z")

</div>

Hi Vilas,

This sounds like a question that should be on the Elasticsearch discuss list. Did you post something there?

You could try to do some queries like what Kibana is doing directly to elasticsearch to see if the performance problem is Kibana or Elasticsearch. On current versions of Kibana, on the Discover tab, if you click the ^ icon under the chart you see a "Statistics" button that shows you;

- Query Duration
- Request Duration
- Hits

That might be useful information for debugging the performance issue.

But if the issue is Elasticsearch you should ask on that discuss list.

Oh, and if you can upgrade your Elasticsearch and Kibana, there's always performance improvements and awesome new features!

Thanks,  
Lee

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2016, 2:40pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/3 "2016-03-24T14:40:03Z")

</div>

What kind of hardware is your cluster deployed on? Why do you have 3 out of 5 data nodes on a single server? What is the rationale behind having 2 client nodes on the same server? How much data do you have? How many indices/shards do you have?

---

<div class="post-metadata">

**Author:** ![vilas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vilas/32/613_2.png) [@vilas](https://discuss.elastic.co/u/vilas)\
**Post date:** [March 24, 2016, 3:50pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/4 "2016-03-24T15:50:46Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> What kind of hardware is your cluster deployed on?

We have limited physical number of physical servers (4) but powerful enough.  
**Type-1** : 2 Servers: Intel(R) Xeon(R)/x86\_64 - 24 CPUs \* 24 Cores - 500 GB RAM  
**Type-2** : 2 Servers: Intel(R) Xeon(R)/x86\_64 - 64 CPUs \* 8 Cores - 250 GB RAM

> [@Christian\_Dahlqvist](#):
>
> Why do you have 3 out of 5 data nodes on a single server?

As the servers are powerful, we thought we would run multiple nodes of ES on single server.  
3 Nodes are running on one of Type-1 server above.

> [@Christian\_Dahlqvist](#):
>
> What is the rationale behind having 2 client nodes on the same server?

Same reason as above. Powerful server. Only one client was running. So thought adding one more would speed up the kibana. Please clarify if this works?

> [@Christian\_Dahlqvist](#):
>
> How many indices/shards do you have?

About 1000 indices. We have large data in one of the index patterns (about 8 GB per index per day). So we close indices older than 2 months of this index pattern.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2016, 4:14pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/5 "2016-03-24T16:14:18Z")

</div>

Are you using shard allocation awareness to ensure that primaries and replicas are spread out across the servers? What kind of storage are you using?

---

<div class="post-metadata">

**Author:** ![vilas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vilas/32/613_2.png) [@vilas](https://discuss.elastic.co/u/vilas)\
**Post date:** [March 24, 2016, 4:36pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/6 "2016-03-24T16:36:10Z")

</div>

We don't have replicas for large indices of one index pattern because we don't have enough space on those servers.  
But for other indices, we have a replica. We use the default config and 5 shards per index.

> [@Christian\_Dahlqvist](#):
>
> What kind of storage are you using?

We are using regular hard disk based memory.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2016, 5:13pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/7 "2016-03-24T17:13:20Z")

</div>

The 3 nodes you have on the single server are likely to generate roughly 3 times the I/O as well compared to the nodes that are hosted on their own servers, assuming the data is well distributed. Are you using dedicated disks for each of the the 3 nodes that are hosted on the same server? What does I/O look like on this server when you are querying?

---

<div class="post-metadata">

**Author:** ![vilas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vilas/32/613_2.png) [@vilas](https://discuss.elastic.co/u/vilas)\
**Post date:** [March 24, 2016, 10:24pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/8 "2016-03-24T22:24:18Z")

</div>

> [@LeeDr](#):
>
> - Query Duration
> - Request Duration

Can you please elaborate the difference between these two?

---

<div class="post-metadata">

**Author:** ![vilas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vilas/32/613_2.png) [@vilas](https://discuss.elastic.co/u/vilas)\
**Post date:** [March 24, 2016, 10:25pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/9 "2016-03-24T22:25:36Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> Are you using dedicated disks for each of the the 3 nodes that are hosted on the same server? What does I/O look like on this server when you are querying?

We are not using dedicated disks. And understand that there would be a lot of I/O.  
So do you suggest to use only one data node per disk??

---

<div class="post-metadata">

**Author:** ![vilas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vilas/32/613_2.png) [@vilas](https://discuss.elastic.co/u/vilas)\
**Post date:** [March 24, 2016, 10:40pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/10 "2016-03-24T22:40:40Z")

</div>

@Christian_Dahlqvist  
Also forgot to mention the fact that, Node6 and Node7 (Clients) are in same physical server which is located in a different data center from other physical servers.  
Do you think that would affect the performance?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 25, 2016, 1:04am UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/11 "2016-03-25T01:04:47Z")

</div>

> [@vilas](#):
>
> So do you suggest to use only one data node per disk??

Not necessarily, but I do suggest you looking at I/O stats during operation to see if this might be a limeting factor causing increased latencies.

> [@vilas](#):
>
> Also forgot to mention the fact that, Node6 and Node7 (Clients) are in same physical server which is located in a different data center from other physical servers. Do you think that would affect the performance?

DEploying across data centers is generally not recommended, and will affect cluster performance. Even though client ondes do not hold data and this limits the amount of data transferred between data centers, client ondes do hold the fluster state and need to be updated when this changes. High latencies can slow dow this process, which can be a problem.

---

<div class="post-metadata">

**Author:** ![vilas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vilas/32/613_2.png) [@vilas](https://discuss.elastic.co/u/vilas)\
**Post date:** [March 25, 2016, 4:55pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/12 "2016-03-25T16:55:48Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> looking at I/O stats during operation

How can I do that? Does elasticsearch gather that stats?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 25, 2016, 5:24pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/13 "2016-03-25T17:24:31Z")

</div>

I believe Marvel keeps track of this, but you can also use operating system tools like e.g. `iostat` on Linux.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:57pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290/14 "2017-07-06T13:57:45Z")

</div>


