# Wildcarded query make elasticsearch cluster unresponsive

**URL:** https://discuss.elastic.co/t/wildcarded-query-make-elasticsearch-cluster-unresponsive/119729
**Category:** Elasticsearch
**Created:** [February 14, 2018, 5:46am UTC](https://discuss.elastic.co/t/wildcarded-query-make-elasticsearch-cluster-unresponsive/119729 "2018-02-14T05:46:05Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Sriram\_P](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Sriram\_P](https://discuss.elastic.co/u/Sriram_P)
#### Post date: [February 14, 2018, 5:46am UTC](https://discuss.elastic.co/t/wildcarded-query-make-elasticsearch-cluster-unresponsive/119729/1 "2018-02-14T05:46:05Z")

</div>

I run the query below on a large elastic search cluster. The cluster bcomes unresponsive

```auto
{
  "size": 10000,
  "query": {
    "bool": {
      "must": [
        {
          "regexp": {
            "message": {
              "value": ".*exception.*"
            }
          }
        },
        {
          "bool": {
            "should": [
              {
                "term": {
                  "beat.hostname": "ip-xxx-xx-xx-xx"
                }
              }
            ]
          }
        },
        {
          "range": {
            "@timestamp": {
              "lt": 1518459660000,
              "format": "epoch_millis",
              "gte": 1518459600000
            }
          }
        }
      ]
    }
  }
}

```

When I remove the wildcarded `.*exception.*` and replace it with any non wildcarded string like `xyz` it returns fast. Though the query uses a wildcarded expression, it also looks for a small time range and a specific host. I would think this is a very simple query. Any reason why elasticsearch server can't handle this query? The cluster has 10 nodes and 20 TB of data.

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [February 14, 2018, 6:42am UTC](https://discuss.elastic.co/t/wildcarded-query-make-elasticsearch-cluster-unresponsive/119729/2 "2018-02-14T06:42:29Z")

</div>

Probably the reason we are saying that wildcards are slow: [Wildcard query | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-wildcard-query.html)

> Note that this query can be slow, as it needs to iterate over many terms. In order to prevent extremely slow wildcard queries, a wildcard term should not start with one of the wildcards \* or ?.

---

<div class="post-metadata">

### Author: ![Sriram\_P](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Sriram\_P](https://discuss.elastic.co/u/Sriram_P)
#### Post date: [February 14, 2018, 6:57am UTC](https://discuss.elastic.co/t/wildcarded-query-make-elasticsearch-cluster-unresponsive/119729/3 "2018-02-14T06:57:43Z")

</div>

Thanks for the response. I read that document before. If you look at the query I posted, I restrict the query based on the timestamp range and the hostname term. I handpicked these values so no documents are matched.  
It still causes the cluster to become unresponsive.

So is it fair to assume that elasticsearch does not optimize the query and randomly picks what field to query first?

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [February 14, 2018, 7:30am UTC](https://discuss.elastic.co/t/wildcarded-query-make-elasticsearch-cluster-unresponsive/119729/4 "2018-02-14T07:30:04Z")

</div>

Put the other queries inside a `filter` clause instead of the `must` clause.  
Or at least, put the worse query at the end.

---

<div class="post-metadata">

### Author: ![Sriram\_P](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Sriram\_P](https://discuss.elastic.co/u/Sriram_P)
#### Post date: [February 14, 2018, 3:17pm UTC](https://discuss.elastic.co/t/wildcarded-query-make-elasticsearch-cluster-unresponsive/119729/5 "2018-02-14T15:17:47Z")

</div>

Thanks for the quick response. I will give that a try. Is there a way I can verify that filter happens first, maybe through a explain plan?

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [February 14, 2018, 7:03pm UTC](https://discuss.elastic.co/t/wildcarded-query-make-elasticsearch-cluster-unresponsive/119729/6 "2018-02-14T19:03:18Z")

</div>

Profile API might give some clues.

I _think_ something like this is coming but I don't remember from the top of my head.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 14, 2018, 7:03pm UTC](https://discuss.elastic.co/t/wildcarded-query-make-elasticsearch-cluster-unresponsive/119729/7 "2018-03-14T19:03:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
