# Query\_string performance

**URL:** <https://discuss.elastic.co/t/query-string-performance/86808>\
**Category:** Kibana\
**Created:** [May 23, 2017, 12:45pm UTC](https://discuss.elastic.co/t/query-string-performance/86808 "2017-05-23T12:45:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![baltendo](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@baltendo](https://discuss.elastic.co/u/baltendo)\
**Post date:** [May 23, 2017, 12:45pm UTC](https://discuss.elastic.co/t/query-string-performance/86808/1 "2017-05-23T12:45:46Z")

</div>

Hi!

We recently upgraded Elasticsearch and Kibana from 5.3.0 to 5.4.0 and since then we experience performance issues with dashboards and visualizations. Here is the query that is generated by Kibana for a visualization on the `.monitoring-es-2-*` index:

```auto
{
  "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "analyze_wildcard": true,
            "query": "*"
          }
        },
        {
          "query_string": {
            "analyze_wildcard": true,
            "query": "*"
          }
        },
        {
          "range": {
            "timestamp": {
              "gte": 1495455394174,
              "lte": 1495541794174,
              "format": "epoch_millis"
            }
          }
        }
      ],
      "must_not": []
    }
  },
  "size": 0,
  "_source": {
    "excludes": []
  },
  "aggs": {
    "2": {
      "date_histogram": {
        "field": "timestamp",
        "interval": "30m",
        "time_zone": "Europe/Berlin",
        "min_doc_count": 1
      },
      "aggs": {
        "3": {
          "terms": {
            "field": "source_node.name",
            "size": 30,
            "order": {
              "1": "desc"
            }
          },
          "aggs": {
            "1": {
              "max": {
                "field": "node_stats.process.cpu.percent"
              }
            }
          }
        }
      }
    }
  },
  "version": true,
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {
        "highlight_query": {
          "bool": {
            "must": [
              {
                "query_string": {
                  "analyze_wildcard": true,
                  "query": "*",
                  "all_fields": true
                }
              },
              {
                "query_string": {
                  "analyze_wildcard": true,
                  "query": "*",
                  "all_fields": true
                }
              },
              {
                "range": {
                  "timestamp": {
                    "gte": 1495455394174,
                    "lte": 1495541794174,
                    "format": "epoch_millis"
                  }
                }
              }
            ],
            "must_not": []
          }
        }
      }
    },
    "fragment_size": 2147483647
  }
}

```

Side note: the `query_string` in the `query` and in the `highlight_query` are duplicated.

To analyze the problem we copied the query into the dev tools (sense) and executed them.  
Using the exact same query results in a response time of 10+ seconds.  
Removing the `query_string` blocks results in a response time of 1+ seconds.

As we experience the problem in Kibana, I decided to post it in this category, but it could be also a problem of Elasticsearch. What do you think?

I quickly compared the results with and without the `query_string` and I don't see any difference. Why is the `query_string` needed/used?

Thanks in advance for your help!

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [May 23, 2017, 1:13pm UTC](https://discuss.elastic.co/t/query-string-performance/86808/2 "2017-05-23T13:13:28Z")

</div>

Hi,

This is definitely a question for Elasticsearch. Can you post it in there?

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![baltendo](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@baltendo](https://discuss.elastic.co/u/baltendo)\
**Post date:** [May 23, 2017, 1:46pm UTC](https://discuss.elastic.co/t/query-string-performance/86808/3 "2017-05-23T13:46:03Z")

</div>

I added also a thread in Elasticsearch:

> [@Query\_string performance issue](https://discuss.elastic.co/t/query-string-performance-issue/86818):
>
> Hi! Initially I posted this issue in Kibana but I was asked to post it here as well: Kibana: [Query\_string performance](https://discuss.elastic.co/t/query-string-performance/86808) We recently upgraded Elasticsearch and Kibana from 5.3.0 to 5.4.0 and since then we experience performance issues with dashboards and visualizations. Here is the query that is generated by Kibana for a visualization on the .monitoring-es-2-\* index: { "query": { "bool": { "must": [ { "query\_string": { "analyze\_wildcard": true, …

But the problem with the duplicated `query_string` blocks is on Kibana side I guess?

BTW: We just found a workaround to improve the performance by disabling the `_all` field and using the `index.query.default_field` which prevents Elasticsearch from looking into every "queryable" field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2017, 1:46pm UTC](https://discuss.elastic.co/t/query-string-performance/86808/4 "2017-06-20T13:46:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
