# Circuit breaker exception resulted in temination of all the nodes of Elasticsearch

**URL:** <https://discuss.elastic.co/t/circuit-breaker-exception-resulted-in-temination-of-all-the-nodes-of-elasticsearch/242783>\
**Category:** Kibana\
**Created:** [July 27, 2020, 4:54pm UTC](https://discuss.elastic.co/t/circuit-breaker-exception-resulted-in-temination-of-all-the-nodes-of-elasticsearch/242783 "2020-07-27T16:54:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [July 27, 2020, 4:54pm UTC](https://discuss.elastic.co/t/circuit-breaker-exception-resulted-in-temination-of-all-the-nodes-of-elasticsearch/242783/1 "2020-07-27T16:54:07Z")

</div>

Hi All,

I am new to ELK and tried load testing for the first time, I did some heavy load testing in ELK and tried to create a report for last three months .When I ran the command . I can see shards started failing and all the elasticsearch nodes and logstash services moved to stopped state. In the logstash logs , I got below error

[2020-07-24T12:31:50,219][INFO][logstash.outputs.elasticsearch][nir-esim-gdsp\_pipeline][c042dc0baedb208c3ba6bede824f0d8ed0fa8c3a85c5914726e4dfce3f7315bb] Retrying individual bulk actions that failed or were rejected by the previous bulk request. {:count=\>1}  
[2020-07-24T12:31:56,732][INFO][logstash.outputs.elasticsearch][first\_pipeline][c042dc0baedb208c3ba6bede824f0d8ed0fa8c3a85c5914726e4dfce3f7315bb] retrying failed action with response code: 429 ({"type"=\>"circuit\_breaking\_exception", "reason"=\>"[parent] Data too large, data for [\<transport\_request\>] would be [1050524440/1001.8mb], which is larger than the limit of [1020054732/972.7mb], real usage: [1050521096/1001.8mb], new bytes reserved: [3344/3.2kb], usages [request=24208/23.6kb, fielddata=38134/37.2kb, in\_flight\_requests=67096/65.5kb, accounting=10372352/9.8mb]", "bytes\_wanted"=\>1050524440, "bytes\_limit"=\>1020054732, "durability"=\>"PERMANENT"})

Can I do some settings that instead of elasticsearch going down, it can just reject or give timeout error in kibana. As ELK cluster going down will pile up all the logs in source system

---

<div class="post-metadata">

**Author:** ![myasonik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/myasonik/32/62369_2.png) [@myasonik](https://discuss.elastic.co/u/myasonik)\
**Post date:** [July 27, 2020, 7:05pm UTC](https://discuss.elastic.co/t/circuit-breaker-exception-resulted-in-temination-of-all-the-nodes-of-elasticsearch/242783/2 "2020-07-27T19:05:25Z")

</div>

Hey @rohitarorait82!

Unfortunately, there's no way to swallow these errors and keep ES up and running while it's overloaded.

I'd recommend reading [this blog post](https://www.elastic.co/blog/why-am-i-seeing-bulk-rejections-in-my-elasticsearch-cluster) about the issue and trying to tune your ES cluster to be a better fit for the data you have.

---

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [July 30, 2020, 7:10am UTC](https://discuss.elastic.co/t/circuit-breaker-exception-resulted-in-temination-of-all-the-nodes-of-elasticsearch/242783/3 "2020-07-30T07:10:56Z")

</div>

Thanks @myasonik for you reply.

I am just trying to run below query in ELK for very huge data. Is there a way to find out maximum time range which I can use in this query.

GET /my\_index/\_search  
{  
"size" :0,  
"aggs": {  
"2": {  
"terms": {  
"field": "API.keyword",  
"order": {  
"1": "desc"  
},  
"size": 500  
},  
"aggs": {  
"1": {  
"cardinality": {  
"field": "correl.keyword"  
}  
},  
"3": {  
"terms": {  
"field": "Consumer.keyword",  
"order": {  
"1": "desc"  
},  
"size": 50  
},  
"aggs": {  
"1": {  
"cardinality": {  
"field": "correl.keyword"  
}  
}  
}  
}  
}  
}  
},  
"query": {  
"bool": {  
"filter": [  
{  
"range": {  
"@timestamp": {  
"gte": "2020-07-30T05:49:39.444Z",  
"lte": "2020-07-30T05:50:39.444Z",  
"format": "strict\_date\_optional\_time"  
}  
}  
}  
]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![myasonik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/myasonik/32/62369_2.png) [@myasonik](https://discuss.elastic.co/u/myasonik)\
**Post date:** [August 4, 2020, 6:46pm UTC](https://discuss.elastic.co/t/circuit-breaker-exception-resulted-in-temination-of-all-the-nodes-of-elasticsearch/242783/4 "2020-08-04T18:46:42Z")

</div>

Hey @rohitarorait82! Sorry about the delayed response. Just talked with our easticsearch team... Ordering terms aggs by cardinality is just a really expensive query so you're prone to run into issues like this.

Some other things I learned:

- The circuit breaker exception _should_ be non-fatal so there might be something else going on there if your nodes are really going down (however it _can_ be fatal sometimes)
- Another thing, the circuit breaker exception gets tripped just when the overall memory is over a certain threshold so there might be something else chewing through some of your available memory, not just this query (though this is an expensive query)
- A [composite agg](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-composite-aggregation.html) should be more efficient if you're trying to see a lot of results but that might affect your logstash setup

---

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [August 6, 2020, 6:07am UTC](https://discuss.elastic.co/t/circuit-breaker-exception-resulted-in-temination-of-all-the-nodes-of-elasticsearch/242783/5 "2020-08-06T06:07:58Z")

</div>

@myasonik Thanks a lot , I will check and try to implement all these suggestions

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 3, 2020, 6:15am UTC](https://discuss.elastic.co/t/circuit-breaker-exception-resulted-in-temination-of-all-the-nodes-of-elasticsearch/242783/7 "2020-09-03T06:15:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
