# 🐌 Poor search performance when searching in data stream indexes

**URL:** <https://discuss.elastic.co/t/poor-search-performance-when-searching-in-data-stream-indexes/315531>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [September 30, 2022, 8:35am UTC](https://discuss.elastic.co/t/poor-search-performance-when-searching-in-data-stream-indexes/315531 "2022-09-30T08:35:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [September 30, 2022, 8:35am UTC](https://discuss.elastic.co/t/poor-search-performance-when-searching-in-data-stream-indexes/315531/1 "2022-09-30T08:35:35Z")

</div>

Hi! 👋

I have a pretty small amount of documents from Metricbeat and I have loaded them into 2 ways into Elasticsearch:

1. Using the default Metricbeat index template and datastream (created by Metricbeat), ILM policy has created 4 indexes with rollover every hour.

2. Writing to a regular index by Metricbeat with index name pattern that contains hour in its name, so also have 3 indexes to search into.

And what I see is that searching in Kibana using the data stream indexes is drastically slow compared to regular indexes search. I have noted that when searching in a data stream, Kibana sends 5 similar search requests with a pretty big delay between each other.

I have recorded a screencast to show this issue [https://take.ms/Cpu48](https://take.ms/Cpu48).

Can you please clarify why that happens? It that some misconfiguration?

Thanks!

---

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [September 30, 2022, 10:47am UTC](https://discuss.elastic.co/t/poor-search-performance-when-searching-in-data-stream-indexes/315531/2 "2022-09-30T10:47:29Z")

</div>

Looks like this is some bug or misconfiguration of the index template created by Metricbeat. When I have created the same index template with the data stream manually (but without default mappings) and ILM, everything works fine.

---

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [September 30, 2022, 8:57pm UTC](https://discuss.elastic.co/t/poor-search-performance-when-searching-in-data-stream-indexes/315531/3 "2022-09-30T20:57:56Z")

</div>

Looks like I should use the default Metricbeat index template settings and mappings, since other apps, like Observability, rely on it. Otherwise, they just don't work.

So that issue is still present.  
Can someone please help?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 10, 2022, 7:35pm UTC](https://discuss.elastic.co/t/poor-search-performance-when-searching-in-data-stream-indexes/315531/4 "2022-10-10T19:35:21Z")

</div>

Hey @Its_Anton,

Thanks for the detailed report. What version of Metricbeat are you using?

I wonder if this is caused by the big number of field mappings included in Metricbeat. Did you have the chance of trying with [Elastic Agent](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html)? It also uses data streams, but one is created for each data set of each integration, with much smaller mappings. This would be more similar to the test you mention that works better.

---

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [October 11, 2022, 10:48am UTC](https://discuss.elastic.co/t/poor-search-performance-when-searching-in-data-stream-indexes/315531/5 "2022-10-11T10:48:00Z")

</div>

Hi, @jsoriano!

I use v8.4.2 for the entire stack. And that is the default mappings that come with Metricbeat, I don't know if you consider it big or not 🙂

Currently, I have all setup with standalone beat services, so I don't plan to migrate to the Agent.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2022, 10:48am UTC](https://discuss.elastic.co/t/poor-search-performance-when-searching-in-data-stream-indexes/315531/6 "2022-11-08T10:48:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
