# Some queries crash my cluster

**URL:** <https://discuss.elastic.co/t/some-queries-crash-my-cluster/11154>\
**Category:** Elasticsearch\
**Created:** [March 14, 2013, 10:32am UTC](https://discuss.elastic.co/t/some-queries-crash-my-cluster/11154 "2013-03-14T10:32:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shadyabhi](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@shadyabhi](https://discuss.elastic.co/u/shadyabhi)\
**Post date:** [March 14, 2013, 10:32am UTC](https://discuss.elastic.co/t/some-queries-crash-my-cluster/11154/1 "2013-03-14T10:32:10Z")

</div>

Hi all,

Sometimes, if I query over lots of indices, my cluster stops indexing stuff  
and takes 100% CPU of one core.

It cries a lot with ConcurrentMarkSweep messages and I could see this trace  
([http://sprunge.us/CYhF](http://sprunge.us/CYhF)) in logs too. logstash-2013.03.02 is actually an  
index which was created on 2nd March. So, it looks like there is some query  
which was executed on that index and it stopped indexing in the cluster.

Is there anything I can do to avoid this thing? I don't want a single  
search query to bring down indexing in cluster.

--  
Regards,  
Abhijeet Rastogi (shadyabhi)

> **[Abhijeet Rastogi - Google+](https://plus.google.com/107316377741966576356/)**
>
> A Google+ profile for Abhijeet Rastogi

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 14, 2013, 10:53am UTC](https://discuss.elastic.co/t/some-queries-crash-my-cluster/11154/2 "2013-03-14T10:53:55Z")

</div>

Hey,

your log shows an out of memory exception. You might solve this problem by  
simply adding more memory to your elasticsearch java virtual machine.

Check for ES\_HEAP\_SIZE at

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

On Thu, Mar 14, 2013 at 11:32 AM, Abhijeet Rastogi  
[abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com)wrote:

> Hi all,
> 
> Sometimes, if I query over lots of indices, my cluster stops indexing  
> stuff and takes 100% CPU of one core.
> 
> It cries a lot with ConcurrentMarkSweep messages and I could see this  
> trace ([http://sprunge.us/CYhF](http://sprunge.us/CYhF)) in logs too. logstash-2013.03.02 is  
> actually an index which was created on 2nd March. So, it looks like there  
> is some query which was executed on that index and it stopped indexing in  
> the cluster.
> 
> Is there anything I can do to avoid this thing? I don't want a single  
> search query to bring down indexing in cluster.
> 
> --  
> Regards,  
> Abhijeet Rastogi (shadyabhi)  
> [Google Workspace Updates: New community features for Google Chat and an update on Currents](https://plus.google.com/107316377741966576356/)
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![shadyabhi](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@shadyabhi](https://discuss.elastic.co/u/shadyabhi)\
**Post date:** [March 14, 2013, 11:46am UTC](https://discuss.elastic.co/t/some-queries-crash-my-cluster/11154/3 "2013-03-14T11:46:52Z")

</div>

Ok, I truely understand that I need more RAM but isn't there a way to limit  
the number of threads/memory used for searching?

I'll prefer a timeout than a ES reaching it's max heap value. This is the  
graph for one of the nodes [http://i.imgur.com/IYly5Hq.png](http://i.imgur.com/IYly5Hq.png) Is it too  
stressed for the node? (Machine has 48GB ram and have set max heap to  
24GB).

It stays at 17-20GB while I'm indexing stuff (and minor searching)..

On Thu, Mar 14, 2013 at 4:23 PM, Alexander Reelsen [alr@spinscale.de](mailto:alr@spinscale.de) wrote:

> Hey,
> 
> your log shows an out of memory exception. You might solve this problem by  
> simply adding more memory to your elasticsearch java virtual machine.
> 
> Check for ES\_HEAP\_SIZE at  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/setup/installation.html)
> 
> On Thu, Mar 14, 2013 at 11:32 AM, Abhijeet Rastogi \<  
> [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com)\> wrote:
> 
> > Hi all,
> > 
> > Sometimes, if I query over lots of indices, my cluster stops indexing  
> > stuff and takes 100% CPU of one core.
> > 
> > It cries a lot with ConcurrentMarkSweep messages and I could see this  
> > trace ([http://sprunge.us/CYhF](http://sprunge.us/CYhF)) in logs too. logstash-2013.03.02 is  
> > actually an index which was created on 2nd March. So, it looks like there  
> > is some query which was executed on that index and it stopped indexing in  
> > the cluster.
> > 
> > Is there anything I can do to avoid this thing? I don't want a single  
> > search query to bring down indexing in cluster.
> > 
> > --  
> > Regards,  
> > Abhijeet Rastogi (shadyabhi)  
> > [Google Workspace Updates: New community features for Google Chat and an update on Currents](https://plus.google.com/107316377741966576356/)
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Regards,  
Abhijeet Rastogi (shadyabhi)

> **[New community features for Google Chat and an update on Currents](https://workspaceupdates.googleblog.com/2023/04/new-community-features-for-google-chat-and-an-update-currents%20.html)**
>
> Note:  This blog post outlines upcoming changes to Google Currents for Workspace users. For information on the previous deprecation of Googl...

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 14, 2013, 12:33pm UTC](https://discuss.elastic.co/t/some-queries-crash-my-cluster/11154/4 "2013-03-14T12:33:51Z")

</div>

Look at thread pool in es docs.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

It should help.

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 14 mars 2013 à 12:46, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) a écrit :

> Ok, I truely understand that I need more RAM but isn't there a way to limit the number of threads/memory used for searching?
> 
> I'll prefer a timeout than a ES reaching it's max heap value. This is the graph for one of the nodes [http://i.imgur.com/IYly5Hq.png](http://i.imgur.com/IYly5Hq.png) Is it too stressed for the node? (Machine has 48GB ram and have set max heap to 24GB).
> 
> It stays at 17-20GB while I'm indexing stuff (and minor searching)..
> 
> On Thu, Mar 14, 2013 at 4:23 PM, Alexander Reelsen [alr@spinscale.de](mailto:alr@spinscale.de) wrote:
> 
> > Hey,
> > 
> > your log shows an out of memory exception. You might solve this problem by simply adding more memory to your elasticsearch java virtual machine.
> > 
> > Check for ES\_HEAP\_SIZE at [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/setup/installation.html)
> > 
> > On Thu, Mar 14, 2013 at 11:32 AM, Abhijeet Rastogi [abhijeet.1989@gmail.com](mailto:abhijeet.1989@gmail.com) wrote:
> > 
> > > Hi all,
> > > 
> > > Sometimes, if I query over lots of indices, my cluster stops indexing stuff and takes 100% CPU of one core.
> > > 
> > > It cries a lot with ConcurrentMarkSweep messages and I could see this trace ([http://sprunge.us/CYhF](http://sprunge.us/CYhF)) in logs too. logstash-2013.03.02 is actually an index which was created on 2nd March. So, it looks like there is some query which was executed on that index and it stopped indexing in the cluster.
> > > 
> > > Is there anything I can do to avoid this thing? I don't want a single search query to bring down indexing in cluster.
> > > 
> > > ## -- Regards, Abhijeet Rastogi (shadyabhi) [Google Workspace Updates: New community features for Google Chat and an update on Currents](https://plus.google.com/107316377741966576356/)
> > > 
> > > You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> ## -- Regards, Abhijeet Rastogi (shadyabhi) [Google Workspace Updates: New community features for Google Chat and an update on Currents](https://plus.google.com/107316377741966576356/)
> 
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:46am UTC](https://discuss.elastic.co/t/some-queries-crash-my-cluster/11154/5 "2017-07-06T02:46:28Z")

</div>


