# Slow searches on a cluster

**URL:** <https://discuss.elastic.co/t/slow-searches-on-a-cluster/47580>\
**Category:** Elasticsearch\
**Created:** [April 17, 2016, 10:53am UTC](https://discuss.elastic.co/t/slow-searches-on-a-cluster/47580 "2016-04-17T10:53:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![LiorY89](https://avatars.discourse-cdn.com/v4/letter/l/5f9b8f/32.png) [@LiorY89](https://discuss.elastic.co/u/LiorY89)\
**Post date:** [April 17, 2016, 10:53am UTC](https://discuss.elastic.co/t/slow-searches-on-a-cluster/47580/1 "2016-04-17T10:53:37Z")

</div>

So i'm making a benchmark for performance tests. I have a cluster with 4 machines -\> all virtual, all with 64GB RAM and 1.5TB Memory. Only one of those 4 machines is master node.  
I Indexed 2 bilion records (each record is 1kb) with 20 shards and replica (so i have now 40 shards)  
each shard is 31.1gb size.  
The records I indexed has many fields, two of them is id and name.  
Now i'm trying to aggragate on id, and sub-aggregate on the name field  
this query is 30 seconds long, and when i'm in kibana, on the nodes screen, I see that 2 nodes are with 0% CPU usage, and the other nodes are 10-15%.  
It looks strange to me that the query is taking so much time, and the machines doesn't work so hard.  
I guess i could add a 5th machine, and i'll get better performance, but i think that with the current hardware I can get also a better search results (a single term query is 10 seconds length)

Am I doing something wrong? Or is it an Elastic limitation?

---

<div class="post-metadata">

**Author:** ![softwaredoug](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/softwaredoug/32/22681_2.png) [@softwaredoug](https://discuss.elastic.co/u/softwaredoug)\
**Post date:** [April 17, 2016, 6:29pm UTC](https://discuss.elastic.co/t/slow-searches-on-a-cluster/47580/2 "2016-04-17T18:29:00Z")

</div>

Are you saying a single term query, without the aggregation, is 10 seconds? Or a single term query including the aggregation is 10 seconds?

Can you share the query you're sending? Or one that recreates the problem?

Also how much RAM is going to JVM? Is enough being left for the OS's file system cache?

---

<div class="post-metadata">

**Author:** ![LiorY89](https://avatars.discourse-cdn.com/v4/letter/l/5f9b8f/32.png) [@LiorY89](https://discuss.elastic.co/u/LiorY89)\
**Post date:** [April 18, 2016, 7:41am UTC](https://discuss.elastic.co/t/slow-searches-on-a-cluster/47580/3 "2016-04-18T07:41:40Z")

</div>

Hey,

each machine has 30GB RAM for ES\_HEAP\_SIZE, and the rest is left for the OS

an example for a query without aggregation:

> GET records/\_search  
> {  
> "size": 1000  
> , "query": {  
> "filtered": {  
> "filter": {  
> "term": {  
> "phoneNumber": "05801001590"  
> }  
> }  
> }  
> }  
> }

phone number is type string, this query took 6000 ms

This is the 2 aggregations query:

> GET records/\_search  
> {  
> "aggs": {  
> "by\_id": {  
> "terms": {  
> "field": "entityId",  
> "size": 5,  
> "order": {  
> "\_count": "desc"  
> }  
> },  
> "aggs": {  
> "by\_name": {  
> "terms": {  
> "field": "name",  
> "size": 1  
> }  
> }  
> }  
> }  
> }  
> }

this query took 30000 ms

each record has an ID, Name, Phone and some other fields (this is version 2.3.1 so by default all fields are default doc\_value)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:58pm UTC](https://discuss.elastic.co/t/slow-searches-on-a-cluster/47580/4 "2017-07-05T22:58:37Z")

</div>


