# Optimize search speed / resource usage by writing good queries?

**URL:** https://discuss.elastic.co/t/optimize-search-speed-resource-usage-by-writing-good-queries/78695
**Category:** Kibana
**Created:** [March 15, 2017, 11:56am UTC](https://discuss.elastic.co/t/optimize-search-speed-resource-usage-by-writing-good-queries/78695 "2017-03-15T11:56:44Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)
#### Post date: [March 15, 2017, 11:56am UTC](https://discuss.elastic.co/t/optimize-search-speed-resource-usage-by-writing-good-queries/78695/1 "2017-03-15T11:56:44Z")

</div>

Hi,

I would like to increase my the search speed in kibana.  
Since I am not that familar with lucene indexes / elasticsearch yet, I would like to ask you for your opinion.

Searching is real easy via kibana. Just type in a word and all events containing the word are given back.  
Now my events have several fields, just like type, payload, message, username, etc.  
For example, if I am searching for a username, does it improve the speed if I search for:  
username: xyz instead of searching for xyz?

I mean, now ES would know, that it only needs to search within that field, but I am not sure, if the indexing is based on fields or on top level of the document.

I just want to optimize my saved queries and want to give the other team members hints to query as resource nicest as possible 😉

PS:  
I am aware of the fact, that I may get also additional events, where the username may occur in a different filed, if not setting the filter for the name. Just think of an example where xyz is ONLY found in the username.  
Thanks Andreas

---

<div class="post-metadata">

### Author: ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)
#### Post date: [March 16, 2017, 11:01am UTC](https://discuss.elastic.co/t/optimize-search-speed-resource-usage-by-writing-good-queries/78695/2 "2017-03-16T11:01:46Z")

</div>

@asp specifying the field that you are searching for text within will generally increase performance. When you don't specify a field, it uses the [Default Field](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#_default_field) of the index which defaults to [\_all](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-all-field.html).

The difference in performance between the two really depends on your data. To see how your queries are performing, you can use the "Spy Panel" highlighted below

 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/1/015f423a2f1edb1301834bf4381c50b5d29b8f15.png)

which will show you the Request that is executed against Elasticsearch

 ![](https://us1.discourse-cdn.com/elastic/original/3X/3/9/39969a18ddd9838c3526d335da09729310486208.png)

and some pertinent Stats, particularly the Request duration

 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/f/2fb87c757f330895083605b2d6223f97e0c1f04c.png)

If you're interested in the performance of a specific query, we have a tool discussed here that will allow you to inspect the specific parts of the query that are taking the most time: [https://www.elastic.co/blog/a-profile-a-day-keeps-the-doctor-away-the-elasticsearch-search-profiler](https://www.elastic.co/blog/a-profile-a-day-keeps-the-doctor-away-the-elasticsearch-search-profiler)

---

<div class="post-metadata">

### Author: ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)
#### Post date: [March 16, 2017, 11:45am UTC](https://discuss.elastic.co/t/optimize-search-speed-resource-usage-by-writing-good-queries/78695/3 "2017-03-16T11:45:24Z")

</div>

thanks a lot for the reply.

Then I can write some guidelines for my team, how to use queries the best way.  
Also the profiler looks very interesting.

Time to download the xpack basic 😉

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 13, 2017, 11:45am UTC](https://discuss.elastic.co/t/optimize-search-speed-resource-usage-by-writing-good-queries/78695/4 "2017-04-13T11:45:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
