# Courier Fetch: 1 of 610 shards failed

**URL:** <https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458>\
**Category:** Kibana\
**Created:** [May 29, 2017, 1:30pm UTC](https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458 "2017-05-29T13:30:57Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Baco](https://avatars.discourse-cdn.com/v4/letter/b/94ad74/32.png) [@Baco](https://discuss.elastic.co/u/Baco)\
**Post date:** [May 29, 2017, 1:30pm UTC](https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458/1 "2017-05-29T13:30:57Z")

</div>

Hello,

Could you help me to understand why I have every times the fallowing message when I try to see the dashboard: Courier Fetch: 1 of 610 shards failed.

I have only a cluster with a node.

Otherwise I don't understand why the shard size is getting high on monitoring panel.

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 30, 2017, 1:04am UTC](https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458/2 "2017-05-30T01:04:03Z")

</div>

Check your ES logs for more on that error.

What sort of data are you sending to ES, and how are you sending it?

---

<div class="post-metadata">

**Author:** ![Baco](https://avatars.discourse-cdn.com/v4/letter/b/94ad74/32.png) [@Baco](https://discuss.elastic.co/u/Baco)\
**Post date:** [May 30, 2017, 7:27am UTC](https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458/3 "2017-05-30T07:27:31Z")

</div>

Thanks for your reply @warkolm

My ES logs is:

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:438) [netty-transport-4.1.9.Final.jar:4.1.9.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:858) [netty-common-4.1.9.Final.jar:4.1.9.Final]  
at java.lang.Thread.run(Thread.java:745) [?:1.8.0\_121]

It's Syslog data I send to ES. I use syslog directly in input plugin.

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 30, 2017, 8:32am UTC](https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458/4 "2017-05-30T08:32:19Z")

</div>

Is there more to that log?

How large is your node? How many indices? How many shards? What version of the stack are you on?

---

<div class="post-metadata">

**Author:** ![Baco](https://avatars.discourse-cdn.com/v4/letter/b/94ad74/32.png) [@Baco](https://discuss.elastic.co/u/Baco)\
**Post date:** [May 30, 2017, 8:50am UTC](https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458/5 "2017-05-30T08:50:20Z")

</div>

Yes @warkolm, there is another logs.

I forget to notice that I had this behavior since x-pack installation: Courier Fetch: 1 of 610 shards failed.  
I have just 1 node, I create two new indexes than logstash-\*. I don't change the number of shards by default which is 5. And in the monitoring panel, I can notice my shard size becoming too high 672 (I don't understand this). I use ES 5.4.0

And another logs are:

[2017-05-30T10:34:59,183][DEBUG][o.e.a.s.TransportSearchAction] [node-ircad] [ircad-2017.20.29][3], node[ZwCaCsUmRwKyyzkAimImfg], [P], s[STARTED], a[id=5oYgUNB\_R6ui5\_\_4ap0NZQ]: Failed to execute [SearchRequest{searchType=QUERY\_THEN\_FETCH, indices=[ircad-2017.38.24, ircad-2017.21.29,

indicesOptions=IndicesOptions[id=39, ignore\_unavailable=true, allow\_no\_indices=true, expand\_wildcards\_open=true, expand\_wildcards\_closed=false, allow\_alisases\_to\_multiple\_indices=true, forbid\_closed\_indices=true], types=[], routing='null', preference='1496133297584', requestCache=null, scroll=null, source={  
"size" : 0,  
"query" : {  
"bool" : {  
"must" : [  
{  
"query\_string" : {  
"query" : "\*",  
"fields" : [],  
"use\_dis\_max" : true,  
"tie\_breaker" : 0.0,  
"default\_operator" : "or",  
"auto\_generate\_phrase\_queries" : false,  
"max\_determinized\_states" : 10000,  
"enable\_position\_increments" : true,  
"fuzziness" : "AUTO",  
"fuzzy\_prefix\_length" : 0,  
"fuzzy\_max\_expansions" : 50,  
"phrase\_slop" : 0,  
"analyze\_wildcard" : true,  
"escape" : false,  
"split\_on\_whitespace" : true,  
"boost" : 1.0  
}  
},  
{

org.elasticsearch.transport.RemoteTransportException: [node-ircad][192.168.228.96:9300][indices:data/read/search[phase/query]]  
Caused by: org.elasticsearch.common.util.concurrent.EsRejectedExecutionException: rejected execution of org.elasticsearch.transport.TransportService$7@2edd31d7 on EsThreadPoolExecutor[search, queue capacity = 1000, org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor@1b862a97[Running, pool size = 7, active threads = 4, queued tasks = 1000, completed tasks = 134139]]  
at org.elasticsearch.common.util.concurrent.EsAbortPolicy.rejectedExecution(EsAbortPolicy.java:50) ~[elasticsearch-5.4.0.jar:5.4.0]  
at java.util.concurrent.ThreadPoolExecutor.reject(ThreadPoolExecutor.java:823) ~[?:1.8.0\_121]  
at java.util.concurrent.ThreadPoolExecutor.execute(ThreadPoolExecutor.java:1369) ~[?:1.8.0\_121]  
at org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor.doExecute(EsThreadPoolExecutor.java:94) ~[elasticsearch-5.4.0.jar:5.4.0]  
at org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor.execute(EsThreadPoolExecutor.java:89) ~[elasticsearch-5.4.0.jar:5.4.0]  
at org.elasticsearch.transport.TransportService.sendLocalRequest(TransportService.java:623) ~[elasticsearch-5.4.0.jar:5.4.0]  
at org.elasticsearch.transport.TransportService.access$000(TransportService.java:73) ~[elasticsearch-5.4.0.jar:5.4.0]  
at org.elasticsearch.transport.TransportService$3.sendRequest(TransportService.java:133) ~[elasticsearch-5.4.0.jar:5.4.0]  
at org.elasticsearch.transport.TransportService.sendRequestInternal(TransportService.java:569) ~[elasticsearch-5.4.0.jar:5.4.0]  
at org.elasticsearch.xpack.security.transport.SecurityServerTransportInterceptor.sendWithUser(SecurityServerTransportInterceptor.java:146) ~[?:?]  
at org.elasticsearch.xpack.security.transport.SecurityServerTransportInterceptor.access$600(SecurityServerTransportInterceptor.java:63) ~[?:?]  
at org.elasticsearch.xpack.security.transport.SecurityServerTransportInterceptor$1.sendRequest(SecurityServerTransportInterceptor.java:128) ~[?:?]

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 30, 2017, 9:32am UTC](https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458/6 "2017-05-30T09:32:56Z")

</div>

> [@Baco](#):
>
> queue capacity = 1000

That means your node is overloaded.

If you only have a single node, I'd say you have too many shards. You should look to use the `_shrink` API on any old index and reduce the shard count. If you have data that is less than ~50GB per index, then shrink them to a single shard.

---

<div class="post-metadata">

**Author:** ![Baco](https://avatars.discourse-cdn.com/v4/letter/b/94ad74/32.png) [@Baco](https://discuss.elastic.co/u/Baco)\
**Post date:** [May 30, 2017, 9:47am UTC](https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458/7 "2017-05-30T09:47:12Z")

</div>

Thanks @warkolm

I will try this and will inform you.

But, why the number of shard increase every day when I take a look to monitoring panel. (see below)  
Initially the number of shard 5. Or, it's the different shard?

![](https://us1.discourse-cdn.com/elastic/original/3X/2/9/298302bc756108fc9609977ff082fd04729f83c2.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 30, 2017, 10:27am UTC](https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458/8 "2017-05-30T10:27:32Z")

</div>

New indices get created every day, which means more shards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2017, 10:27am UTC](https://discuss.elastic.co/t/courier-fetch-1-of-610-shards-failed/87458/9 "2017-06-27T10:27:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
