# What would be the lowest-cost, highest-impact change I can make to decrease response times?

**URL:** <https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919>\
**Category:** Elasticsearch\
**Created:** [September 24, 2015, 1:16pm UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919 "2015-09-24T13:16:20Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![gx14](https://avatars.discourse-cdn.com/v4/letter/g/3e96dc/32.png) [@gx14](https://discuss.elastic.co/u/gx14)\
**Post date:** [September 24, 2015, 1:16pm UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/1 "2015-09-24T13:16:20Z")

</div>

(Asked [on SO](https://stackoverflow.com/questions/32762157/elasticsearch-what-would-be-the-lowest-cost-highest-impact-change-i-can-make-t) but thought that this place is probably better)

Unguided beginners in any field often find themselves barking up the wrong tree in trying to solve a problem — this question is asked in hoping that it'll vector my approach in a more direct path towards solving the problem.

* * *

On to the question:

I'm about a month into working with ES and so far it's been awesome. I've been incrementally indexing to ES from a set of data I've got in CSV, and I'm beginning to encounter slow response times. I want to bring the response time down, but don't know what's a good way / the best way to approach it.

My research thus far tells me that it really depends on a number of variables. So, listed below are details on the ES variables which might help you with writing an answer:

- **Shards & Stuff**
  - I say "& Stuff" because I don't know enough to know what's significant here.
  - Running the default ES settings, 5 shards, 1 node.
  - Running index-time-search-as-you-type, exactly as-is from the [ES guide](https://www.elastic.co/guide/en/elasticsearch/guide/current/_index_time_search_as_you_type.html). There's a bit in there which `PUT`s settings for the indices: `"number_of_shards": 1`. I'm not sure how that affects things.

- **Index**
  - 2 indices with similar mappings (mirror a DB, so don't want to combine them)
  - Multi-language, but at the moment I only care about English.
  - As mentioned above, configured for index-time-search-as-you-type (min: 3, max: 20).

- **Documents**
  - Have currently indexed ~1mil documents.
  - Have total of ~4mil documents to index.
  - Very short documents, like 5 fields of 10 english words per doc.
  - Total CSV filesize of all ~4mil rows is only ~400MB.

- **Queries**
  - Main query is run as a bool (should) query.
  - Heavy on score scripting.
  - Heavy on script-sorted aggregations.
  - Fuzzy search (fuzziness: 1).

- **Hardware**
  - Running [Linode's $20/mo VPS](https://www.linode.com/pricing).

- **Response Time**
  - Queries with very high frequencies (typically a single English word) in the index are taking forever (~7-9000ms) to return results.
  - More specific queries (\>=2 eng words) return more acceptable response times (~2-3000ms).
  - Ideally, all response times should be \<2s.

If there are other variables which are important, and I've missed out, let me know and I'll edit them in.

Thank you!

---

<div class="post-metadata">

**Author:** ![gx14](https://avatars.discourse-cdn.com/v4/letter/g/3e96dc/32.png) [@gx14](https://discuss.elastic.co/u/gx14)\
**Post date:** [September 24, 2015, 9:08pm UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/2 "2015-09-24T21:08:47Z")

</div>

I turned [caching](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules-shard-query-cache.html) on (kinda a stop-gap measure) and it has helped a bunch. Meets my needs for now.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 24, 2015, 9:34pm UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/3 "2015-09-24T21:34:05Z")

</div>

With only 2Gb of RAM on the entire system, it'd be upgrade the hardware.

---

<div class="post-metadata">

**Author:** ![softwaredoug](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/softwaredoug/32/22681_2.png) [@softwaredoug](https://discuss.elastic.co/u/softwaredoug)\
**Post date:** [September 25, 2015, 1:31am UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/4 "2015-09-25T01:31:10Z")

</div>

I would recommend actually being comfortable profiling Elasticsearch yourself, its a great way to learn and start to dig into the code. It'll point at your problems most directly.

That being said when I see this

> Queries with very high frequencies (typically a single English word) in the index are taking forever (~7-9000ms) to return results.

I wonder if you use stemming and stopwords? You probably do. But anything you can do to decrease the size of the term dictionary can help here.

By

> "typically a single English word"

do you mean the query is a single word? A single term query takes 7-9 seconds. I'd definitely be interested to see what else you're doing at query time like scripting, etc. A single term query should be really fast even on modest hardware.

---

<div class="post-metadata">

**Author:** ![gx14](https://avatars.discourse-cdn.com/v4/letter/g/3e96dc/32.png) [@gx14](https://discuss.elastic.co/u/gx14)\
**Post date:** [September 25, 2015, 3:47am UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/5 "2015-09-25T03:47:23Z")

</div>

> profiling Elasticsearch yourself

@softwaredoug I began digging around my cluster for information, and found out that it's only got 1 shard (well, duh, I set it to 1 shard, see first post). Though that should actually be the most-optimised case (as compared to getting more primary shards), considering that I've only got ES running on 1 node. Increasing the number of primary shards should only decrease the response times. But I'll probably do it anyway, in order to over-allocate shards.

Also, I tested queries with varying numbers of documents in the index. I found out that the response time is proportional to the number of docs in the index (500k docs might take ~3s, and 1M docs might take ~6-7s. Didn't use any tools to count the response times, but my observations seem to be pretty consistent.

I'm guessing this is happening because of the combination of 2 factors: (1) My scores are scripted (not TF/IDF) and (2) I'm querying using a bool (should, constant\_score) query. So what might be happening is that the ES shard is matching all the docs which contain that single, common term, resulting in a large set of docs to compute a score for, then evaluating the score for all of those docs, ordering them, then returning the results.

> I wonder if you use stemming and stopwords?

No stopping and no stemming, in fact, I'm querying with `"analyzer": "simple",`. It's (probably) what I wrote about in the previous paragraph that's causing all this bloat.

> With only 2Gb of RAM on the entire system, it'd be upgrade the hardware.

@warkolm Yeah, I just read the [ES guide on hardware](https://www.elastic.co/guide/en/elasticsearch/guide/current/hardware.html). I really should be working with _at least_ 8Gb of RAM. I wonder if Response Time/RAM/Number of Documents can be looked at as 3 factors in a balanced equation, though? Meaning, if I double the RAM and keep the no. of docs constant, can I reasonably expect response times to be cut in half?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 25, 2015, 3:50am UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/6 "2015-09-25T03:50:16Z")

</div>

> [@gx14](#):
>
> Increasing the number of primary shards should only decrease the response times

Not necessarily.

> [@gx14](#):
>
> My scores are scripted

That's gunna play a BIG part, scripting is slow.

And in relation to your comment on mine, the thing you also need to factor into cost is your own time. What's the point in spending N hours with a fine tooth comb on this when increasing available resources could get you better results for 20% of your hourly rate?  
It's not that simple, I know, but keep it in mind.

---

<div class="post-metadata">

**Author:** ![gx14](https://avatars.discourse-cdn.com/v4/letter/g/3e96dc/32.png) [@gx14](https://discuss.elastic.co/u/gx14)\
**Post date:** [September 25, 2015, 3:55am UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/7 "2015-09-25T03:55:39Z")

</div>

Gotcha.

What do you think about this part:

> [@gx14](#):
>
> I wonder if Response Time/RAM/Number of Documents can be looked at as 3 factors in a balanced equation, though? Meaning, if I double the RAM and keep the no. of docs constant, can I reasonably expect response times to be cut in half?

If I upgrade the RAM on the node, I probably can expect that to directly impact response times... Right?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 25, 2015, 4:21am UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/8 "2015-09-25T04:21:52Z")

</div>

It will, yes.

---

<div class="post-metadata">

**Author:** ![gx14](https://avatars.discourse-cdn.com/v4/letter/g/3e96dc/32.png) [@gx14](https://discuss.elastic.co/u/gx14)\
**Post date:** [September 25, 2015, 4:30am UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/9 "2015-09-25T04:30:46Z")

</div>

Nice. Thanks!

---

<div class="post-metadata">

**Author:** ![Srinath\_C](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srinath_c/32/48806_2.png) [@Srinath\_C](https://discuss.elastic.co/u/Srinath_C)\
**Post date:** [October 2, 2015, 11:09am UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/10 "2015-10-02T11:09:00Z")

</div>

Enabling doc\_values on fields in the mapping has greatly improved our query response times. Especially if you are aggregating and sorting. Note though that it results in 1.5-2 times the storage requirement.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 3, 2015, 8:41am UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/11 "2015-10-03T08:41:24Z")

</div>

That seems _very_ high given the small size of doc values?

---

<div class="post-metadata">

**Author:** ![Srinath\_C](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srinath_c/32/48806_2.png) [@Srinath\_C](https://discuss.elastic.co/u/Srinath_C)\
**Post date:** [October 3, 2015, 2:14pm UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/12 "2015-10-03T14:14:10Z")

</div>

Sorry, I'd like to clarify - it resulted in 1.5-2 times the storage for my case where document size is ~1.7k each document has ~40 fields of various types mostly long values.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:46pm UTC](https://discuss.elastic.co/t/what-would-be-the-lowest-cost-highest-impact-change-i-can-make-to-decrease-response-times/29919/13 "2017-07-05T23:46:57Z")

</div>


