设置只读索引是否可提升Elasticsearch集群性能?
Will Marking Old Elasticsearch 6.x Indexes as Read-Only Improve Cluster Performance?
Definitely—marking your older, no-longer-updated daily indexes as read-only will absolutely help boost your Elasticsearch 6.x cluster's performance, and here's a breakdown of why that works:
- Cuts down on unnecessary background work: Writable indexes, even if no writes are occurring, still run processes like segment merging, translog synchronization, and metadata checks. Setting an index to read-only disables all these write-related overheads, freeing up CPU, memory, and disk I/O resources that can be redirected to your active, writable daily indexes (the ones Logstash is still feeding data into).
- Eliminates cluster state churn: Every time an index's metadata (like mappings, settings, or aliases) changes, the entire cluster has to sync this updated state across all nodes. Read-only indexes lock down their metadata, preventing accidental or unnecessary changes. This reduces the frequency of cluster state updates, which is a big win—especially for larger clusters where state syncs can consume significant resources.
- Supercharges caching: Elasticsearch can be far more aggressive with caching for read-only indexes. Since the data never changes, caches like the query cache, fielddata cache, and segment caches don't need to be invalidated or refreshed constantly. This means faster query response times for old data, and less overall cache-related resource usage.
- Unlocks smarter resource allocation: Once indexes are read-only, you can safely adjust shard allocation (like moving them to less powerful "warm" nodes, or consolidating shards) to free up resources on your "hot" nodes that handle the daily write load from Logstash. The read-only flag is a critical prerequisite for making these kinds of optimizations without risking data corruption.
Quick Tip for ES 6.x
To mark all your old daily indexes as read-only, you can run this command:
PUT /your-index-pattern-*/_settings { "index.blocks.write": true }
Just replace your-index-pattern-* with the actual pattern of your older indexes (e.g., logstash-2024-* for indexes from 2024 and earlier).
内容的提问来源于stack exchange,提问作者Azeros
相关产品推荐
相关产品推荐

