Poor Performance - Cluster

(ElasticBeats) #1


Most of my system is dragging, especially when running large queries... Does my data seem out of control? I only have 12 winlogbeat clients pushing event logs into the stack..

2 nodes
1,269 indices
12,674 shards
5,751,097 docs

(Christian Dahlqvist) #2

Given the cluster size and data volume you have far too many shards. Have a look at this blog post for some practical guidelines.

(ElasticBeats) #3

I saw that but it does not say how?

(Christian Dahlqvist) #4

One way is to use the shrink API to shrink each index down to a single primary shard, but that only reduces the shard count by a factor of 5 if we assume default settings have been used. You probably need to reduce the shard count by more than that, and may therefore need to reindex your data and perhaps go from daily indices to monthly ones (possibly with a single primary shard).

(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.