# Significant increase in elasticsearch query time after upgrade to 6.2.3

**URL:** <https://discuss.elastic.co/t/significant-increase-in-elasticsearch-query-time-after-upgrade-to-6-2-3/137685>\
**Category:** Elasticsearch\
**Created:** [June 27, 2018, 7:54pm UTC](https://discuss.elastic.co/t/significant-increase-in-elasticsearch-query-time-after-upgrade-to-6-2-3/137685 "2018-06-27T19:54:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![zubinr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zubinr/32/99020_2.png) [@zubinr](https://discuss.elastic.co/u/zubinr)\
**Post date:** [June 27, 2018, 7:54pm UTC](https://discuss.elastic.co/t/significant-increase-in-elasticsearch-query-time-after-upgrade-to-6-2-3/137685/1 "2018-06-27T19:54:45Z")

</div>

We recently upgraded our ELK stack from 5.6.6. to 6.2.3  
In 5.6.6 with the \_all field enabled if a user didn't specify a field, the query would hit the \_all field and get the results  
In 6.2.3 with the \_all field disabled, if a user doesn't specify a field, elasticsearch looks at all the fields. This results in a significant increase in query time and search thread pools being more saturated.

Has anyone faced a similar issue?  
Is these a way to block searches where a key field is not specified?

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [June 28, 2018, 2:53pm UTC](https://discuss.elastic.co/t/significant-increase-in-elasticsearch-query-time-after-upgrade-to-6-2-3/137685/2 "2018-06-28T14:53:37Z")

</div>

You can get back to a similar behavior if you `copy_to` the fields into a custom "all" field. Should have a similar level of performance too.

I'm assuming your referring to `query_string` queries? I don't believe there is a way to forbid "field-less" queries. But you can set the `default_field` to a specific field (which may be empty) as a way to prevent hitting all the fields. Or you can configure the `index.query.default_field` index setting to point to a specific field so you don't have to modify the query itself.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2018, 2:53pm UTC](https://discuss.elastic.co/t/significant-increase-in-elasticsearch-query-time-after-upgrade-to-6-2-3/137685/3 "2018-07-26T14:53:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
