# Query\_string performance issue

**URL:** <https://discuss.elastic.co/t/query-string-performance-issue/86818>\
**Category:** Elasticsearch\
**Created:** [May 23, 2017, 1:32pm UTC](https://discuss.elastic.co/t/query-string-performance-issue/86818 "2017-05-23T13:32:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![baltendo](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@baltendo](https://discuss.elastic.co/u/baltendo)\
**Post date:** [May 23, 2017, 1:32pm UTC](https://discuss.elastic.co/t/query-string-performance-issue/86818/1 "2017-05-23T13:32:12Z")

</div>

Hi!

Initially I posted this issue in Kibana but I was asked to post it here as well:  
Kibana: [Query\_string performance](https://discuss.elastic.co/t/query-string-performance/86808?u=baltendo)

We recently upgraded Elasticsearch and Kibana from 5.3.0 to 5.4.0 and since then we experience performance issues with dashboards and visualizations. Here is the query that is generated by Kibana for a visualization on the .monitoring-es-2-\* index:

```auto
{
  "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "analyze_wildcard": true,
            "query": "*"
          }
        },
        {
          "query_string": {
            "analyze_wildcard": true,
            "query": "*"
          }
        },
        {
          "range": {
            "timestamp": {
              "gte": 1495455394174,
              "lte": 1495541794174,
              "format": "epoch_millis"
            }
          }
        }
      ],
      "must_not": []
    }
  },
  "size": 0,
  "_source": {
    "excludes": []
  },
  "aggs": {
    "2": {
      "date_histogram": {
        "field": "timestamp",
        "interval": "30m",
        "time_zone": "Europe/Berlin",
        "min_doc_count": 1
      },
      "aggs": {
        "3": {
          "terms": {
            "field": "source_node.name",
            "size": 30,
            "order": {
              "1": "desc"
            }
          },
          "aggs": {
            "1": {
              "max": {
                "field": "node_stats.process.cpu.percent"
              }
            }
          }
        }
      }
    }
  },
  "version": true,
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {
        "highlight_query": {
          "bool": {
            "must": [
              {
                "query_string": {
                  "analyze_wildcard": true,
                  "query": "*",
                  "all_fields": true
                }
              },
              {
                "query_string": {
                  "analyze_wildcard": true,
                  "query": "*",
                  "all_fields": true
                }
              },
              {
                "range": {
                  "timestamp": {
                    "gte": 1495455394174,
                    "lte": 1495541794174,
                    "format": "epoch_millis"
                  }
                }
              }
            ],
            "must_not": []
          }
        }
      }
    },
    "fragment_size": 2147483647
  }
}

```

Side note: the query\_string in the query and in the highlight\_query are duplicated.

To analyze the problem we copied the query into the dev tools (sense) and executed them.  
Using the exact same query results in a response time of 10+ seconds.  
Removing the query\_string blocks results in a response time of 1+ seconds.

As we experience the problem in Kibana, I decided to post it in this category, but it could be also a problem of Elasticsearch. What do you think?

I quickly compared the results with and without the query\_string and I don't see any difference. Why is the query\_string needed/used?

Thanks in advance for your help!

---

<div class="post-metadata">

**Author:** ![baltendo](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@baltendo](https://discuss.elastic.co/u/baltendo)\
**Post date:** [May 23, 2017, 1:48pm UTC](https://discuss.elastic.co/t/query-string-performance-issue/86818/2 "2017-05-23T13:48:47Z")

</div>

We found a workaround for the problem by disabling the `_all` field and using `index.query.default_field` to avoid search every "queryable" field in the mapping.

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [June 7, 2017, 2:07pm UTC](https://discuss.elastic.co/t/query-string-performance-issue/86818/3 "2017-06-07T14:07:20Z")

</div>

Hi @baltendo

I was wondering, can you see how the query is being rewritten with and without the `query_string` parts? You should be able to do (replace `yourindex` with your index name):

```
POST /yourindex/_validate/query?rewrite&explain
{
  "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "analyze_wildcard": true,
            "query": "*"
          }
        },
        {
          "query_string": {
            "analyze_wildcard": true,
            "query": "*"
          }
        },
        {
          "range": {
            "timestamp": {
              "gte": 1495455394174,
              "lte": 1495541794174,
              "format": "epoch_millis"
            }
          }
        }
      ],
      "must_not": []
    }
  }
}

```

And then the same thing without the `query_string` parts

```
POST /yourindex/_validate/query?rewrite&explain
{
  "query": {
    "bool": {
      "must": [
        {
          "range": {
            "timestamp": {
              "gte": 1495455394174,
              "lte": 1495541794174,
              "format": "epoch_millis"
            }
          }
        }
      ],
      "must_not": []
    }
  }
}

```

Can you run those and paste the results here so I can see how it's being rewritten? When I locally run this the query is rewritten as `+*:* +*:*` for the query\_string parts.

---

<div class="post-metadata">

**Author:** ![baltendo](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@baltendo](https://discuss.elastic.co/u/baltendo)\
**Post date:** [June 16, 2017, 9:51am UTC](https://discuss.elastic.co/t/query-string-performance-issue/86818/4 "2017-06-16T09:51:04Z")

</div>

Hi @dakrone!

We fixed our performance issues when using Kibana by specifying a default query field. So I think this changes also influences the data that you want me to post here, right?

Nevertheless this is the result for the `query_string` approach:

```auto
{
      "index": "yourindex",
      "valid": true,
      "explanation": """+ConstantScore(_field_names:yourFieldName) +ConstantScore(_field_names:yourFieldName) +MatchNoDocsQuery["User requested "match_none" query."]"""
}

```

And for the none `query_string` approach:

```auto
{
      "index": "yourindex",
      "valid": true,
      "explanation": """MatchNoDocsQuery["User requested "match_none" query."]"""
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2017, 9:51am UTC](https://discuss.elastic.co/t/query-string-performance-issue/86818/5 "2017-07-14T09:51:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [July 20, 2017, 1:54pm UTC](https://discuss.elastic.co/t/query-string-performance-issue/86818/6 "2017-07-20T13:54:24Z")

</div>

To follow-up on this, [https://github.com/elastic/elasticsearch/pull/25726](https://github.com/elastic/elasticsearch/pull/25726) has been opened and will address the performance issues with the query.
