# Performance of Multiple index patterns vs. a single index pattern

**URL:** <https://discuss.elastic.co/t/performance-of-multiple-index-patterns-vs-a-single-index-pattern/132905>\
**Category:** Elasticsearch\
**Created:** [May 23, 2018, 12:45am UTC](https://discuss.elastic.co/t/performance-of-multiple-index-patterns-vs-a-single-index-pattern/132905 "2018-05-23T00:45:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [May 23, 2018, 12:45am UTC](https://discuss.elastic.co/t/performance-of-multiple-index-patterns-vs-a-single-index-pattern/132905/1 "2018-05-23T00:45:48Z")

</div>

Hi all,

I have 28 types of logs which total up to hundreds of millions event per hour. The indexes are named as following:

- log\_type\_1-
- log\_type\_2-
- log\_type\_3-
- log\_type\_n-

For search and aggregation, is there performance difference between using an single `log_*` index pattern vs. creating an index pattern for each log type (e.g., log\_type\_1-\*)?

If I use `log_*` and search for `type:type_1`, would Kibana be smart enough to skip all other indexes that don't contain `type1`, or does it have to actually search through all indexes under `log_*`?

I did a quick test on Search and Visualization and didn't see any big difference in response time between `log_*` and `log_type_1-*`, but since our logs are growing quickly, any performance tips help alot.

---

<div class="post-metadata">

**Author:** ![RahulD](https://avatars.discourse-cdn.com/v4/letter/r/da6949/32.png) [@RahulD](https://discuss.elastic.co/u/RahulD)\
**Post date:** [May 23, 2018, 3:53pm UTC](https://discuss.elastic.co/t/performance-of-multiple-index-patterns-vs-a-single-index-pattern/132905/2 "2018-05-23T15:53:49Z")

</div>

As far as I know if you run a log\_\* it will query all indexes even if you filter on type\_1 inside the query. The indexes which are not type\_1 will return 0 counts but they certainly will be queried which might add some overhead to your query timings...

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [May 23, 2018, 5:34pm UTC](https://discuss.elastic.co/t/performance-of-multiple-index-patterns-vs-a-single-index-pattern/132905/3 "2018-05-23T17:34:55Z")

</div>

> [@RahulD](#):
>
> The indexes which are not type\_1 will return 0 counts but they certainly will be queried which might add some overhead to your query timings...

Yeah, I'm just wondering how much overhead is added since using `log_*` has multiple benefits

- Simple index pattern management
- Simple field formatter compared to having to change field format for tens of index patterns
- Aggregation across multiple log types

Search Profiler in Dev Tools shows quite a lot of overhead, but actually Search or Visualization between log\_\* and log\_type\_1-\* shows little to no overhead. I hope someone at Elastic can confirm this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2018, 5:34pm UTC](https://discuss.elastic.co/t/performance-of-multiple-index-patterns-vs-a-single-index-pattern/132905/4 "2018-06-20T17:34:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
