I re-ran the query. Correction - It returns 200+ hits (still a tiny percent)
The query profile is
"profile" : {
"shards" : [
{
"id" : "[7VyrRwY7RsaNsG9Ku_4mHA][dns-2022.01.31][1]",
"searches" : [
{
"query" : [
{
"type" : "BooleanQuery",
"description" : "#@timestamp:[1643604891852 TO 1643634378873] #source_ip:{10.15.54.82} #destination_ip:{10.11.100.100} #ConstantScore(query:update.googleapis.com) #ConstantScore(sensor:ids10)",
"time_in_nanos" : 275082934,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 101,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 2170938,
"match" : 493532,
"next_doc_count" : 101,
"score_count" : 101,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 102298,
"advance_count" : 1,
"score" : 43834,
"build_scorer_count" : 2,
"create_weight" : 785962,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 271486370
},
"children" : [
{
"type" : "IndexOrDocValuesQuery",
"description" : "@timestamp:[1643604891852 TO 1643634378873]",
"time_in_nanos" : 539188,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 101,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 359860,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 61779,
"advance_count" : 102,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 5184,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 112365
}
},
{
"type" : "PointInSetQuery",
"description" : "source_ip:{10.15.54.82}",
"time_in_nanos" : 256816,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 45866,
"match" : 0,
"next_doc_count" : 101,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 90563,
"advance_count" : 189,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 1979,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 118408
}
},
{
"type" : "PointInSetQuery",
"description" : "destination_ip:{10.11.100.100}",
"time_in_nanos" : 267025297,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 0,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 64188,
"advance_count" : 102,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 1103,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 266960006
}
},
{
"type" : "ConstantScoreQuery",
"description" : "ConstantScore(query:update.googleapis.com)",
"time_in_nanos" : 860151,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 0,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 683555,
"advance_count" : 290,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 98812,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 77784
},
"children" : [
{
"type" : "TermQuery",
"description" : "query:update.googleapis.com",
"time_in_nanos" : 472118,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 0,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 390704,
"advance_count" : 290,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 8992,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 72422
}
}
]
},
{
"type" : "ConstantScoreQuery",
"description" : "ConstantScore(sensor:ids10)",
"time_in_nanos" : 661630,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 0,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 636967,
"advance_count" : 102,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 9263,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 15400
},
"children" : [
{
"type" : "TermQuery",
"description" : "sensor:ids10",
"time_in_nanos" : 540330,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 0,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 526480,
"advance_count" : 102,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 2442,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 11408
}
}
]
}
]
}
],
"rewrite_time" : 91333,
"collector" : [
{
"name" : "SimpleTopScoreDocCollector",
"reason" : "search_top_hits",
"time_in_nanos" : 502790
}
]
}
],
"aggregations" : [ ],
"fetch" : {
"type" : "fetch",
"description" : "",
"time_in_nanos" : 25039205,
"breakdown" : {
"load_stored_fields" : 7341896,
"load_stored_fields_count" : 101,
"next_reader" : 18375,
"next_reader_count" : 1
},
"debug" : {
"stored_fields" : [
"_id",
"_routing",
"_source"
]
},
"children" : [
{
"type" : "FetchSourcePhase",
"description" : "",
"time_in_nanos" : 58257,
"breakdown" : {
"process_count" : 101,
"process" : 54538,
"next_reader" : 3719,
"next_reader_count" : 1
},
"debug" : {
"fast_path" : 101
}
}
]
}
},
{
"id" : "[gIa422qtRymC2yCgUX0BRg][dns-2022.01.31][0]",
"searches" : [
{
"query" : [
{
"type" : "BooleanQuery",
"description" : "#@timestamp:[1643604891852 TO 1643634378873] #source_ip:{10.15.54.82} #destination_ip:{10.11.100.100} #ConstantScore(query:update.googleapis.com) #ConstantScore(sensor:ids10)",
"time_in_nanos" : 260444552,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 123,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 1808261,
"match" : 305415,
"next_doc_count" : 123,
"score_count" : 123,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 74258,
"advance_count" : 1,
"score" : 39799,
"build_scorer_count" : 2,
"create_weight" : 676729,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 257540090
},
"children" : [
{
"type" : "IndexOrDocValuesQuery",
"description" : "@timestamp:[1643604891852 TO 1643634378873]",
"time_in_nanos" : 321341,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 123,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 198400,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 38862,
"advance_count" : 124,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 4536,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 79543
}
},
{
"type" : "PointInSetQuery",
"description" : "source_ip:{10.15.54.82}",
"time_in_nanos" : 219884,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 43394,
"match" : 0,
"next_doc_count" : 123,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 62331,
"advance_count" : 215,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 1492,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 112667
}
},
{
"type" : "PointInSetQuery",
"description" : "destination_ip:{10.11.100.100}",
"time_in_nanos" : 254418599,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 0,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 45270,
"advance_count" : 124,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 547,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 254372782
}
},
{
"type" : "ConstantScoreQuery",
"description" : "ConstantScore(query:update.googleapis.com)",
"time_in_nanos" : 813078,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 0,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 691533,
"advance_count" : 338,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 56703,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 64842
},
"children" : [
{
"type" : "TermQuery",
"description" : "query:update.googleapis.com",
"time_in_nanos" : 471987,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 0,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 402021,
"advance_count" : 338,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 9690,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 60276
}
}
]
},
{
"type" : "ConstantScoreQuery",
"description" : "ConstantScore(sensor:ids10)",
"time_in_nanos" : 385064,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 0,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 361817,
"advance_count" : 124,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 9280,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 13967
},
"children" : [
{
"type" : "TermQuery",
"description" : "sensor:ids10",
"time_in_nanos" : 309240,
"breakdown" : {
"set_min_competitive_score_count" : 0,
"match_count" : 0,
"shallow_advance_count" : 0,
"set_min_competitive_score" : 0,
"next_doc" : 0,
"match" : 0,
"next_doc_count" : 0,
"score_count" : 0,
"compute_max_score_count" : 0,
"compute_max_score" : 0,
"advance" : 296305,
"advance_count" : 124,
"score" : 0,
"build_scorer_count" : 3,
"create_weight" : 2716,
"shallow_advance" : 0,
"create_weight_count" : 1,
"build_scorer" : 10219
}
}
]
}
]
}
],
"rewrite_time" : 103901,
"collector" : [
{
"name" : "SimpleTopScoreDocCollector",
"reason" : "search_top_hits",
"time_in_nanos" : 419100
}
]
}
],
"aggregations" : [ ],
"fetch" : {
"type" : "fetch",
"description" : "",
"time_in_nanos" : 11602835,
"breakdown" : {
"load_stored_fields" : 7225743,
"load_stored_fields_count" : 123,
"next_reader" : 27007,
"next_reader_count" : 1
},
"debug" : {
"stored_fields" : [
"_id",
"_routing",
"_source"
]
},
"children" : [
{
"type" : "FetchSourcePhase",
"description" : "",
"time_in_nanos" : 82529,
"breakdown" : {
"process_count" : 123,
"process" : 78512,
"next_reader" : 4017,
"next_reader_count" : 1
},
"debug" : {
"fast_path" : 123
}
}
]
}
}
]
}