# 503: SearchPhaseExecutionException\[Failed to execute phase \[query\], all shards failed\]

**URL:** <https://discuss.elastic.co/t/503-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/14683>\
**Category:** Elasticsearch\
**Created:** [December 3, 2013, 5:09pm UTC](https://discuss.elastic.co/t/503-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/14683 "2013-12-03T17:09:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Skylar\_Saveland](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skylar_saveland/32/1938_2.png) [@Skylar\_Saveland](https://discuss.elastic.co/u/Skylar_Saveland)\
**Post date:** [December 3, 2013, 5:09pm UTC](https://discuss.elastic.co/t/503-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/14683/1 "2013-12-03T17:09:26Z")

</div>

Hello,

I have a newbie question. What is the basic meaning of this error and where  
do I go to debug it?

{  
"error": "SearchPhaseExecutionException[Failed to execute phase [query],  
all shards failed]",  
"status": 503  
}

I'm starting elasticsearch with logstash on a single machine:

/usr/bin/java -Des.path.data=/../data/ -jar /../logstash-1.2.1-flatjar.jar  
agent -f /../server.conf -- web

Does there appear to be anything wrong with that cmdline?

server.conf is:

input {  
udp {  
port =\> 8070  
codec =\> "json"  
}  
}  
output {  
elasticsearch {  
embedded =\> true  
}  
}

Looks ok?

I have a couple of queries which are doing fine:

POST logstash-2013.12.03/\_search  
{"query":{"filtered":{"query":{"bool":{"should":[{"query\_string":{"query":  
"\*"}}]}},"filter":{"bool":{"must":[{"match\_all":{}},{"range":{"@timestamp":{  
"from":1383496126260,"to":1386088126260}}},{"bool":{"must":[{"match\_all"  
:{}}]}}]}}}},"highlight":{"fields":{},"fragment\_size":2147483647,"pre\_tags"  
:["@start-highlight@"],"post\_tags":["@end-highlight@"]},"size":500,"sort":[{  
"@timestamp":{"order":"desc"}}]}

POST logstash-2013.12.03/\_search  
{"facets":{"0":{"date\_histogram":{"field":"@timestamp","interval":"12h"},  
"facet\_filter":{"fquery":{"query":{"filtered":{"query":{"query\_string":{  
"query":"\*"}},"filter":{"bool":{"must":[{"match\_all":{}},{"range":{  
"@timestamp":{"from":1383496126260,"to":1386088126260}}},{"bool":{"must":[{  
"match\_all":{}}]}}]}}}}}}}},"size":0}

But, then, I try to step back to the previous index (?) with a similar  
search and it doesn't work:

POST logstash-2013.12.02/\_search  
{"facets":{"0":{"date\_histogram":{"field":"@timestamp","interval":"12h"},  
"facet\_filter":{"fquery":{"query":{"filtered":{"query":{"query\_string":{  
"query":"\*"}},"filter":{"bool":{"must":[{"match\_all":{}},{"range":{  
"@timestamp":{"from":1383496126260,"to":1386088126260}}},{"bool":{"must":[{  
"match\_all":{}}]}}]}}}}}}}},"size":0}

Perhaps the problem is that I tried to "purge" at one point with something  
like this:

#!/usr/bin/perl

my($days)=shift || 90;  
my($STATUS)='curl -s [http://localhost:9200/\_status](http://localhost:9200/_status)';  
my($DELETE)='curl -s -XDELETE [http://localhost:9200/](http://localhost:9200/)';  
my($data)=`$STATUS`; $data=~s/:/=\>/g; $data=~s/true/1/g; $data=~s/false/0/g;  
my($ds)=eval($data);  
my(@indicies)=sort(keys(%{$ds-\>{'indices'}}));  
my($index, $result);

while(@indicies\>$days) {  
$index=shift(@indicies);  
print $index, ": ";  
system("$DELETE$index");  
print "\n";  
}

I don't know perl; and, I don't know where this snippet came from 😕 But,  
since the index in question is not \>90 days old and since it appears to  
still be there (albeit hobbled), I don't think this would be the problem.

Zeroth, is there anything obviously wrong with what I'm doing?  
First, what is the meaning of the error and how should I remedy the current  
situation?  
Second, does the above perl snippet seem like a proper way to purge old  
logs or is there a better way at the ready?

Thank You,  
Skylar

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/00a2ab21-9514-4037-b6dc-9cf8ff92884b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/00a2ab21-9514-4037-b6dc-9cf8ff92884b%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:03am UTC](https://discuss.elastic.co/t/503-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/14683/2 "2017-07-06T02:03:34Z")

</div>


