# Why is catch-all field slower in 6.2 compared to 2.4?

**URL:** <https://discuss.elastic.co/t/why-is-catch-all-field-slower-in-6-2-compared-to-2-4/124374>\
**Category:** Elasticsearch\
**Created:** [March 16, 2018, 11:43pm UTC](https://discuss.elastic.co/t/why-is-catch-all-field-slower-in-6-2-compared-to-2-4/124374 "2018-03-16T23:43:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ar21](https://avatars.discourse-cdn.com/v4/letter/a/c57346/32.png) [@ar21](https://discuss.elastic.co/u/ar21)\
**Post date:** [March 16, 2018, 11:43pm UTC](https://discuss.elastic.co/t/why-is-catch-all-field-slower-in-6-2-compared-to-2-4/124374/1 "2018-03-16T23:43:29Z")

</div>

We upgraded a 2.4 cluster to 6.2 cluster using the reindex from remote approach. In 2.4, we were using the catch-all `_all` field to perform searches and were seeing response times under 500 ms for all our queries.

In 6.2, the `_all` field is no longer available for the new index, so we ended up creating a new text type field called `all` like `"all": {"type": "text"}` and set `copy_to` on all our other fields (about 2000 of them). But now, searches on this new catch-all field `all` are taking 2 to 10 times longer than the search on the 2.4 `_all` field. (We flushed the caches on both clusters before performing the queries.)

Both clusters are single data center, single node 8GB memory on the same AWS zone, hosted through elastic cloud. Both indices have the same number of documents (about 6M) and have about 150 Lucene segment files.

The 2.4 cluster though is being used by a staging app, which might send some queries to it every few minutes, when testers are testing things. Is there any caching (other than ES caches themselves) that might be the reason for this? I am still at a loss as to why the 6.2 queries are this much slower.

---

<div class="post-metadata">

**Author:** ![diranged](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diranged/32/4065_2.png) [@diranged](https://discuss.elastic.co/u/diranged)\
**Post date:** [April 10, 2018, 10:11pm UTC](https://discuss.elastic.co/t/why-is-catch-all-field-slower-in-6-2-compared-to-2-4/124374/2 "2018-04-10T22:11:46Z")

</div>

@Ar21, did you ever resolve this? We also are migrating from 2.4 -\> 6.2 and seeing slow catch all queries. We're not using the `_all` field directly, but we see in Kibana 6.2 that if we search for something simple like `"cron:session"` the result will take 50+ seconds to come back. If we are specific and search for `some_message_field:"cron:session"` then the result comes back in ~800ms.

---

<div class="post-metadata">

**Author:** ![ar21](https://avatars.discourse-cdn.com/v4/letter/a/c57346/32.png) [@ar21](https://discuss.elastic.co/u/ar21)\
**Post date:** [April 11, 2018, 12:08am UTC](https://discuss.elastic.co/t/why-is-catch-all-field-slower-in-6-2-compared-to-2-4/124374/3 "2018-04-11T00:08:01Z")

</div>

No, I didn't get an answer from anyone at elastic so far (as you can see here). I didn't have a chance to benchmark it more thoroughly either, so I don't have an answer.

In your case ensure that Elasticsearch isn't thinking that `cron` is a field name since it is immediately followed by a `:`.

---

<div class="post-metadata">

**Author:** ![diranged](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diranged/32/4065_2.png) [@diranged](https://discuss.elastic.co/u/diranged)\
**Post date:** [April 11, 2018, 10:14pm UTC](https://discuss.elastic.co/t/why-is-catch-all-field-slower-in-6-2-compared-to-2-4/124374/4 "2018-04-11T22:14:13Z")

</div>

So I actually figured it out on our end. When you don't specify a field name, in ES 6 and Kibana 6, a default search parameter `default_field: "*"` is added by Kibana. Even if Kibana did not add that, ElasticSearch would add `default_field: "*.*"`. (\*\*)

To resolve this, we added a `copy_to: "all" mapping to all of our fields, and then reconfigured Kibana to use`all`as the`default\_field`. This resolves the speed issues entirely.

Unfortunately, we don;'t have the mapping quite right yet.. so we are still having issues. I opened up another post about it here: [Proper Template Mapping for ES/Kibana 6.2.3](https://discuss.elastic.co/t/proper-template-mapping-for-es-kibana-6-2-3/127700)

\*\*: [https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2018, 10:14pm UTC](https://discuss.elastic.co/t/why-is-catch-all-field-slower-in-6-2-compared-to-2-4/124374/5 "2018-05-09T22:14:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
