# The queries for numeric fields are slower after upgraded the cluster from 2.4.5 to 5.6.3

**URL:** <https://discuss.elastic.co/t/the-queries-for-numeric-fields-are-slower-after-upgraded-the-cluster-from-2-4-5-to-5-6-3/121620>\
**Category:** Elasticsearch\
**Created:** [February 27, 2018, 9:35am UTC](https://discuss.elastic.co/t/the-queries-for-numeric-fields-are-slower-after-upgraded-the-cluster-from-2-4-5-to-5-6-3/121620 "2018-02-27T09:35:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zzzxf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zzzxf/32/28207_2.png) [@Zzzxf](https://discuss.elastic.co/u/Zzzxf)\
**Post date:** [February 27, 2018, 9:35am UTC](https://discuss.elastic.co/t/the-queries-for-numeric-fields-are-slower-after-upgraded-the-cluster-from-2-4-5-to-5-6-3/121620/1 "2018-02-27T09:35:25Z")

</div>

### Cluster info

_PS: two cluster with same nodes,docs_  
**Elasticsearch version** : 2.4.5/5.6.3  
**JVM version** : java8  
**OS version** : Linux CentOS 6  
**Nodes** : 32(data/master)

### Problem

The queries for numeric fields are slower after upgrading the cluster from 2.4.5 to 5.6.3. The avg and tp99 response time of 5.x cluster increase almost twice as 2.x.

- Query  
The field `xxx_id` is numeric. The query contains 500~1000 random `xxx_id`.  
`{ "from": 0, "size": 1000, "timeout": "5000ms", "query": { "query_string": { "query": "xxx_id:(3976321 2681125 3395902 565629 1473422... )" } } }`

- Result of 5.x

- Result of 2.x  
`{ "took": 688, "timed_out": false, "_shards": { "total": 4, "successful": 4, "failed": 0 }, "hits": { "total": 75350, "max_score": 0, "hits": [...] } }`

### Solution?

Is it due to the changing of numeric data-structure in 5.0? Can I reindex the field as keyword to solve?

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [March 2, 2018, 5:29pm UTC](https://discuss.elastic.co/t/the-queries-for-numeric-fields-are-slower-after-upgraded-the-cluster-from-2-4-5-to-5-6-3/121620/2 "2018-03-02T17:29:33Z")

</div>

> [@Zzzxf](#):
>
> Is it due to the changing of numeric data-structure in 5.0? Can I reindex the field as keyword to solve?

Basically, yes.

In ES 5.x, numerics use a new datastructure (BKD tree). This allows better compression, faster numeric operations and lower memory usage... but it is not ideal for "point lookups" like a `term` query. E.g. it is designed for numeric style operations like ranges, but not single value lookups.

If that field is only used for exact-match lookups, you can re-index it as a `keyword`. Keyword fields are optimized for exact-match lookups and will be a lot faster.

More info: [Tune for search speed | Elasticsearch Guide [master] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/master/tune-for-search-speed.html#_map_identifiers_as_literal_keyword_literal)

To dive a bit more into technicals, the BKD datastructure doesn't support sorted iteration, so it has to collect all matches, sort the array and then return an iterator to that sorted array (paraphrasing). That process happens during the `build_scorer` step. This process isn't bad when dealing with numeric ranges since the cost is amortized over all the values that are being iterated over, but can get expensive when asking for a bunch of individual points.

2.x didn't have BKD trees, hence the difference in performance.

---

<div class="post-metadata">

**Author:** ![ddorian43](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddorian43/32/36093_2.png) [@ddorian43](https://discuss.elastic.co/u/ddorian43)\
**Post date:** [March 3, 2018, 11:50am UTC](https://discuss.elastic.co/t/the-queries-for-numeric-fields-are-slower-after-upgraded-the-cluster-from-2-4-5-to-5-6-3/121620/3 "2018-03-03T11:50:30Z")

</div>

Is there any special encoding done to the terms when it sees that they're all `numbers` ? Kinda like it's done with `_id` in 6+.

---

<div class="post-metadata">

**Author:** ![Zzzxf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zzzxf/32/28207_2.png) [@Zzzxf](https://discuss.elastic.co/u/Zzzxf)\
**Post date:** [March 17, 2018, 11:45am UTC](https://discuss.elastic.co/t/the-queries-for-numeric-fields-are-slower-after-upgraded-the-cluster-from-2-4-5-to-5-6-3/121620/4 "2018-03-17T11:45:05Z")

</div>

Thank you very much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2018, 11:45am UTC](https://discuss.elastic.co/t/the-queries-for-numeric-fields-are-slower-after-upgraded-the-cluster-from-2-4-5-to-5-6-3/121620/5 "2018-04-14T11:45:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
