# Query Performace Help

**URL:** <https://discuss.elastic.co/t/query-performace-help/38993>\
**Category:** Elasticsearch\
**Created:** [January 12, 2016, 2:55pm UTC](https://discuss.elastic.co/t/query-performace-help/38993 "2016-01-12T14:55:54Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ananth](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@ananth](https://discuss.elastic.co/u/ananth)\
**Post date:** [January 12, 2016, 2:55pm UTC](https://discuss.elastic.co/t/query-performace-help/38993/1 "2016-01-12T14:55:54Z")

</div>

Hi,

We are getting logs from multiple ips thus a single index can have docs from multiple ips.

I need to categorise set of ips into one group. As of now i am using OR query to filter those group logs.

Method1 Example:  
(ip1 OR ip2 OR .... OR ip26)

Now i am planning to add one extra field to index say group\_name, which has information regarding what are all the ips belonging to this group.(ip1 to ip26 --\> group1 and ip27 to ip30 --\>group2). Now searching method will change as,

Method2 Example  
group\_name:group1

I would like to know how much performance gain (index may have 100 million documents) i will get if i migrated to method2 ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 14, 2016, 7:08am UTC](https://discuss.elastic.co/t/query-performace-help/38993/2 "2016-01-14T07:08:08Z")

</div>

Hard to say really as there are so many unknowns, but it should be quicker.  
You'd be better off testing.

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [January 14, 2016, 9:12am UTC](https://discuss.elastic.co/t/query-performace-help/38993/3 "2016-01-14T09:12:48Z")

</div>

+1 to what Mark said

---

<div class="post-metadata">

**Author:** ![ebuildy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebuildy/32/6070_2.png) [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Post date:** [January 14, 2016, 12:07pm UTC](https://discuss.elastic.co/t/query-performace-help/38993/4 "2016-01-14T12:07:30Z")

</div>

You could also use filtered alias ([https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-aliases.html#filtered](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-aliases.html#filtered)) it performs well and can be cached.

---

<div class="post-metadata">

**Author:** ![ananth](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@ananth](https://discuss.elastic.co/u/ananth)\
**Post date:** [January 14, 2016, 12:27pm UTC](https://discuss.elastic.co/t/query-performace-help/38993/5 "2016-01-14T12:27:58Z")

</div>

Adrien/Mark/Thomas Thanks for the suggestions. I will try with test data and report back.

---

<div class="post-metadata">

**Author:** ![ananth](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@ananth](https://discuss.elastic.co/u/ananth)\
**Post date:** [April 19, 2016, 10:01am UTC](https://discuss.elastic.co/t/query-performace-help/38993/6 "2016-04-19T10:01:27Z")

</div>

Having one more field(group\_name) gives 70% speed improvement tested with 10million docs from 13 unique ips.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:58pm UTC](https://discuss.elastic.co/t/query-performace-help/38993/7 "2017-07-05T22:58:06Z")

</div>


