# Slow script query

**URL:** <https://discuss.elastic.co/t/slow-script-query/75555>\
**Category:** Elasticsearch\
**Created:** [February 17, 2017, 8:03pm UTC](https://discuss.elastic.co/t/slow-script-query/75555 "2017-02-17T20:03:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashokm](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@ashokm](https://discuss.elastic.co/u/ashokm)\
**Post date:** [February 17, 2017, 8:03pm UTC](https://discuss.elastic.co/t/slow-script-query/75555/1 "2017-02-17T20:03:02Z")

</div>

We have a 4 node cluster. Searching On a index with 40k records is taking upto 3 secs. It used to take less than a second like 400ms but now in last couple of weeks, it started slowing down. We dont see much of GC in the logs

We are on ES 1.4.2. 2 Nodes are allocated 31 Gb of 64 GB heap and other 2 nodes are allocated 15GB of 32 GB heap

```
us_zip_codes/_search
{
  "query": {
    "filtered": {
      "query": {
        "match_all": {}
      },
      "filter": {
        "script": {
          "script": "doc['zip_code'].values.findIndexOf{ srcVal -> param1.any{ it =~ /^(?i).*\\Q${srcVal}\\E.*/}} !=-1",
          "lang": "groovy",
          "params": {
            "param1": [
              "94555-2750"
            ]
          }
        }
      }
    }
  }
}

```

us\_zip\_codes has 5 digit zip\_codes and we want to find a match when have a 9 digit code. I am using above script. How do i troubleshot this issue?

Also, is there a better way to re-write that query. Any help is greatly appreciated

---

<div class="post-metadata">

**Author:** ![ashokm](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@ashokm](https://discuss.elastic.co/u/ashokm)\
**Post date:** [February 25, 2017, 7:24pm UTC](https://discuss.elastic.co/t/slow-script-query/75555/2 "2017-02-25T19:24:01Z")

</div>

We restarted the cluster last night and query performance is back to normal. Can someone give me some idea about what resource ES servers could have been holding to cause the slowness.

Note that, before cluster restart I cleared the cache multiple times and but that didn't help.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 27, 2017, 9:37am UTC](https://discuss.elastic.co/t/slow-script-query/75555/3 "2017-02-27T09:37:50Z")

</div>

Hey,

in Elasticsearch 2.3 there were memory leaks with groovy scripts. You may have hit one in that pretty ancient version as well. This is just a wild guess, if you need to debug this further, you should analyze a heap dump probably.

--Alex

---

<div class="post-metadata">

**Author:** ![ashokm](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@ashokm](https://discuss.elastic.co/u/ashokm)\
**Post date:** [February 27, 2017, 4:54pm UTC](https://discuss.elastic.co/t/slow-script-query/75555/4 "2017-02-27T16:54:18Z")

</div>

Thanks Alex. We are planning to upgrade to 2.4.4 pretty soon. But looks like that may not help either based on this discussion

> <https://github.com/elastic/elasticsearch/issues/18079>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2017, 4:54pm UTC](https://discuss.elastic.co/t/slow-script-query/75555/5 "2017-03-27T16:54:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
