# Alert rule for standard cluster alerts: search\_phase\_execution\_exception \[illegal\_argument\_exception\]

**URL:** <https://discuss.elastic.co/t/alert-rule-for-standard-cluster-alerts-search-phase-execution-exception-illegal-argument-exception/284668>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [September 21, 2021, 2:46am UTC](https://discuss.elastic.co/t/alert-rule-for-standard-cluster-alerts-search-phase-execution-exception-illegal-argument-exception/284668 "2021-09-21T02:46:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jrykowski-huron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jrykowski-huron/32/69454_2.png) [@jrykowski-huron](https://discuss.elastic.co/u/jrykowski-huron)\
**Post date:** [September 21, 2021, 2:46am UTC](https://discuss.elastic.co/t/alert-rule-for-standard-cluster-alerts-search-phase-execution-exception-illegal-argument-exception/284668/1 "2021-09-21T02:46:51Z")

</div>

7.14.1  
Platinum license

Setting up brand new cluster, and have configured metricbeat style monitoring of cluster (separate elasticsearch for monitoring).

Entered setup mode and did the add of standard alerts. Looks like these rules got created but am seeing Error status on all.

- CCR read exceptions
- CPU Usage
- Cluster health
- Disk Usage
- Elasticsearch version mismatch
- Kibana version mismatch
- License expiration
- Memory Usage (JVM)

Error that is shown for each....

> search\_phase\_execution\_exception: [illegal\_argument\_exception] Reason: no mapping found for `cluster_uuid` in order to collapse on; [illegal\_argument\_exception]

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 21, 2021, 2:56am UTC](https://discuss.elastic.co/t/alert-rule-for-standard-cluster-alerts-search-phase-execution-exception-illegal-argument-exception/284668/2 "2021-09-21T02:56:23Z")

</div>

> [@jrykowski-huron](#):
>
> Platinum license

You should definitely raise a request with your Support engineer then 🙂

---

<div class="post-metadata">

**Author:** ![jrykowski-huron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jrykowski-huron/32/69454_2.png) [@jrykowski-huron](https://discuss.elastic.co/u/jrykowski-huron)\
**Post date:** [September 28, 2021, 9:03pm UTC](https://discuss.elastic.co/t/alert-rule-for-standard-cluster-alerts-search-phase-execution-exception-illegal-argument-exception/284668/3 "2021-09-28T21:03:10Z")

</div>

#self-hosted

Hi, did reach out to support for guidance, and the root cause was that I'd done monitoring alert setup on the actual production Kibana... But instead I needed to setup Kibana on the dedicated monitor cluster. Makes sense I guess thinking about it.

Also I had to enable the nodes with role 'remote\_cluster\_client' to get things working fully.

All good now! Alerts setup with PagerDuty actions as well so we're cookin' with fire now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 26, 2021, 9:03pm UTC](https://discuss.elastic.co/t/alert-rule-for-standard-cluster-alerts-search-phase-execution-exception-illegal-argument-exception/284668/4 "2021-10-26T21:03:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
