# Kibana Logs UI query match\_all

**URL:** <https://discuss.elastic.co/t/kibana-logs-ui-query-match-all/210786>\
**Category:** Kibana\
**Created:** [December 5, 2019, 9:43pm UTC](https://discuss.elastic.co/t/kibana-logs-ui-query-match-all/210786 "2019-12-05T21:43:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![delphi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/delphi/32/52397_2.png) [@delphi](https://discuss.elastic.co/u/delphi)\
**Post date:** [December 5, 2019, 9:43pm UTC](https://discuss.elastic.co/t/kibana-logs-ui-query-match-all/210786/1 "2019-12-05T21:43:29Z")

</div>

Hi.

I'm using Kibana Logs UI to view my logs from my k8s pods. Although, when I do a simple query such as " **kubernetes.pod.name: foo.bar"** , I can check a high load on cluster and all Stack hangs.

Is that query doing a "match\_all" documents from all matched indices? Is there way to deal with that?  
(Other cached queries is ok).

_Architecture:_ All my Stack is 7.4.2 (except Metricbeat 7.3.2) and running on k8s (Elastic Official Helm charts)

- FIlebeat+Metricbeat (daemonsets) -\> Elasticsearch

- APM Agents -\> APM Server -\> Elasticsearch

- Kibana -\> Elasticsearch

- Elasticsearch: Hot+Warm

1. 03 hot nodes: 1TB SSD + 8CPU + 28GB RAM
2. 03 warm nodes: 2TB SSD + 4CPU + 16GB RAM
3. 03 shards - 0 Replica
4. Active indices -\> Hot nodes
5. Read-only indices -\> Warm nodes
6. I'm using ILM (rollover indices to warm nodes with 60GB (20gb/shard) and delete them after 20 days)

Index rate is 25k/s

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2020, 9:43pm UTC](https://discuss.elastic.co/t/kibana-logs-ui-query-match-all/210786/2 "2020-01-02T21:43:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
