# My search query is really slow

**URL:** <https://discuss.elastic.co/t/my-search-query-is-really-slow/235418>\
**Category:** Elasticsearch\
**Created:** [June 2, 2020, 11:09pm UTC](https://discuss.elastic.co/t/my-search-query-is-really-slow/235418 "2020-06-02T23:09:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Devon\_Yoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devon_yoo/32/45284_2.png) [@Devon\_Yoo](https://discuss.elastic.co/u/Devon_Yoo)\
**Post date:** [June 2, 2020, 11:09pm UTC](https://discuss.elastic.co/t/my-search-query-is-really-slow/235418/1 "2020-06-02T23:09:55Z")

</div>

I indexed millions of documents already and it as `id` and `words`.  
Both are text.  
In `words`, there are about 900 numeric words with white space between words.  
for example `12 13 15 234 5454 346 3477 ... 935383 1283129` (about 900 words)  
I believe these words are broken into multiple keywords when it's indexed.

Index mapping:

```auto
    id : text
    words : text

```

And I want to search by another `words` which also has 900 numeric words. So I created my search query like below:

My search query:

```auto
    {
        "size": 1,
        "query": {
            "function_score": {
                "query": {
                    "match_all": {
                        "boost": 1
                    }
                },
                "functions": [
                    {
                        "filter": {
                            "match": {
                                "words": {
                                    "query": "17932",
                                    "operator": "OR",
                                    "prefix_length": 0,
                                    "max_expansions": 50,
                                    "fuzzy_transpositions": true,
                                    "lenient": false,
                                    "zero_terms_query": "NONE",
                                    "auto_generate_synonyms_phrase_query": true,
                                    "boost": 1
                                }
                            }
                        },
                        "weight": 1
                    },
                    ... ***there are 900 filters***...
                    {
                        "filter": {
                            "match": {
                                "words": {
                                    "query": "16516932",
                                    "operator": "OR",
                                    "prefix_length": 0,
                                    "max_expansions": 50,
                                    "fuzzy_transpositions": true,
                                    "lenient": false,
                                    "zero_terms_query": "NONE",
                                    "auto_generate_synonyms_phrase_query": true,
                                    "boost": 1
                                }
                            }
                        },
                        "weight": 1
                    }
                ],
                "score_mode": "sum",
                "max_boost": 3.4028235e+38,
                "min_score": 100,
                "boost": 1
            }
        },
        "_source": {
            "includes": [
                "id"
            ],
            "excludes": []
        },
        "sort": [
            {
                "_score": {
                    "order": "desc"
                }
            }
        ]
    }

```

It was working fine when I had less number of documents indexed in my elasticsearch.  
But the query started getting timeout.

I have tried many things to optimize the cluster

1. I have enough number of nodes shards and replicas.
2. Index is turned off so CPU utilization was low.
3. Changed to instance type with more CPUs.

I think the last thing I can try is to fix the search query to speed up its execution. Does anyone have any idea?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 3, 2020, 7:23am UTC](https://discuss.elastic.co/t/my-search-query-is-really-slow/235418/2 "2020-06-03T07:23:52Z")

</div>

Can you describe the expected behaviour of you query? Are you looking to find documents that contain all 900 words queried? If that is the case, have you tried concatenating the words into a space separated string and use this in a single match query with minimum\_should\_match set to 100%?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [June 3, 2020, 10:44am UTC](https://discuss.elastic.co/t/my-search-query-is-really-slow/235418/3 "2020-06-03T10:44:07Z")

</div>

Would a `terms` query be simpler?

```
"terms": {"words": [1,2]}

```

This worked for me on a text field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 1, 2020, 10:44am UTC](https://discuss.elastic.co/t/my-search-query-is-really-slow/235418/4 "2020-07-01T10:44:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
