# Discover: Request Timout after 30000ms / mapping size is larger than 10MB Version 6.3.1

**URL:** <https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863>\
**Category:** Kibana\
**Created:** [August 5, 2019, 6:12pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863 "2019-08-05T18:12:16Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Asa\_Zalles-Milner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asa_zalles-milner/32/43809_2.png) [@Asa\_Zalles-Milner](https://discuss.elastic.co/u/Asa_Zalles-Milner)\
**Post date:** [August 5, 2019, 6:12pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/1 "2019-08-05T18:12:17Z")

</div>

I am getting the request timeout anytime i do a across all fields search in kibana, this used to work fine, it is only at a 15 minute timespan, but can't figure out what is going on.

It does seem maybe only my beats indices that has the issue (in two different separate clusters, but unsure where to start, thinking it is something to do with the mappings for these indices.

in the developer console when i'm using query profiler I'm seeing the following and I think it relates....  
kibana.bundle.js:3 mapping size is larger than 10MB (16.564489364624023 MB). ignoring..  
that is happening even when I specify the field to search.

I found my cluster state is 59 MB... i'm guessing that could also be part of the problem?  
What can I do about it?

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [August 5, 2019, 9:49pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/2 "2019-08-05T21:49:10Z")

</div>

The request timeout can be bumped up using `elasticsearch.requestTimeout` in kibana.yml.

Alternatively we need to find a way to limit the search or improve the cluster performance. At the Kibana level - is limiting the number of fields you're searching across an option? Maybe less data (e.g. increasing the beats interval) At the elasticsaerch level, we can dig into number of shards, replicas, and hardware.

---

<div class="post-metadata">

**Author:** ![kumar8055](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@kumar8055](https://discuss.elastic.co/u/kumar8055)\
**Post date:** [August 6, 2019, 5:29am UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/3 "2019-08-06T05:29:44Z")

</div>

Hi @Asa_Zalles-Milner,

Can you provide more cluster details like how many nodes, how many indices and what is the cluster size?

---

<div class="post-metadata">

**Author:** ![Asa\_Zalles-Milner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asa_zalles-milner/32/43809_2.png) [@Asa\_Zalles-Milner](https://discuss.elastic.co/u/Asa_Zalles-Milner)\
**Post date:** [August 6, 2019, 4:55pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/4 "2019-08-06T16:55:35Z")

</div>

So i did discover something interesting after this post.  
It is only in kibana the query times out, but if I do a direct elasticsearch query, it returns in under the timeout.  
The use case is "someone doesn't know what field the data is in" and needs to do a quick query to find the data so they can filter down to the index. I find it very odd that it is both metricbeat and filebeat exhibiting the problem, and the two different clusters have different amount of data.

2 different clusters are exhibiting the same behavior, 3 different sets of indices in each cluster exhibit the same problem, all are set to 1 shard with 1 replica  
Data nodes are 32gb ram, 16vcpu, 1tb of disk (c5.4xlarge)

1 is 24 data nodes . 929 indices.  
2 is 44 data nodes. 910 indices

It doesn't feel like the 30 second timeout is really the issue, it feels like something else is wrong with those indices in being queried by kibana, this is happening even when I just search the two individual index patterns of metricbeat and filebeat.

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [August 6, 2019, 6:21pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/5 "2019-08-06T18:21:17Z")

</div>

Okay, interesting. Kibana's query probably isn't a direct match to what's being queried directly . I'd tend to agree that something's wrong ont he kibana side, that sounds like plenty of hardware for querying metricbeat data.

If you get a chance can you share the \_msearch query and timestamps in your browsers developer tools and if there's anything surrounding it that looks out of place?

---

<div class="post-metadata">

**Author:** ![Asa\_Zalles-Milner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asa_zalles-milner/32/43809_2.png) [@Asa\_Zalles-Milner](https://discuss.elastic.co/u/Asa_Zalles-Milner)\
**Post date:** [August 6, 2019, 6:43pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/6 "2019-08-06T18:43:01Z")

</div>

Here is the exact lucene queries being used. i'm mostly looking at filebeat right now, since that is what clued me in, but it is also on the metricbeat index.  
does NOT work. env.overall:prod AND "app-name"  
does work env.overall:prod AND message: "app-name"

I have 3 different filebeat indices (for different ENV) and all of them are exhibiting this same problem.

I am only looking back at 15 minutes and it is timing out btw.

Here is the request payload I believe. (fished out of the kibana that is coming back and then adjusted to not query message specifically).  
{  
"version": true,  
"size": 1000,  
"sort": [  
{  
"@timestamp": {  
"order": "desc",  
"unmapped\_type": "boolean"  
}  
}  
],  
"\_source": {  
"excludes":   
},  
"aggs": {  
"2": {  
"date\_histogram": {  
"field": "@timestamp",  
"interval": "30s",  
"time\_zone": "UTC",  
"min\_doc\_count": 1  
}  
}  
},  
"stored\_fields": [  
"_"  
],  
"script\_fields": {},  
"docvalue\_fields": [  
"@timestamp",  
"event.created",  
"suricata.eve.flow.end",  
"suricata.eve.flow.start",  
"suricata.eve.timestamp",  
"suricata.eve.tls.notafter",  
"suricata.eve.tls.notbefore"  
],  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "env.overall:prod AND "container-service-proxy"",  
"analyze\_wildcard": true,  
"default\_field": "_"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": 1565115340106,  
"lte": 1565116240106,  
"format": "epoch\_millis"  
}  
}  
}  
],  
"filter": ,  
"should": ,  
"must\_not":   
}  
},  
"highlight": {  
"pre\_tags": [  
"@kibana-highlighted-field@"  
],  
"post\_tags": [  
"@/kibana-highlighted-field@"  
],  
"fields": {  
"\*": {}  
},  
"fragment\_size": 2147483647  
}  
}

Do you think that mapping size being greater than 10MB is okay? (i think not, since I can get the result querying directly...) But just asking.

---

<div class="post-metadata">

**Author:** ![Asa\_Zalles-Milner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asa_zalles-milner/32/43809_2.png) [@Asa\_Zalles-Milner](https://discuss.elastic.co/u/Asa_Zalles-Milner)\
**Post date:** [August 7, 2019, 6:58pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/7 "2019-08-07T18:58:09Z")

</div>

No seeing any sign of an error in the logs or anything like that.

---

<div class="post-metadata">

**Author:** ![Asa\_Zalles-Milner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asa_zalles-milner/32/43809_2.png) [@Asa\_Zalles-Milner](https://discuss.elastic.co/u/Asa_Zalles-Milner)\
**Post date:** [August 9, 2019, 2:46am UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/8 "2019-08-09T02:46:05Z")

</div>

Any Idea?

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [August 12, 2019, 9:36pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/9 "2019-08-12T21:36:09Z")

</div>

Yes I would tend to agree the mapping size combined with the full text query `AND "container-service-proxy"` is adding some work. Does the query work with just `env.overall:prod`? Can we limit the search for `container-service-proxy` to a single field?

Otherwise things look mostly okay, nothing jumps out on first glance.

---

<div class="post-metadata">

**Author:** ![Asa\_Zalles-Milner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asa_zalles-milner/32/43809_2.png) [@Asa\_Zalles-Milner](https://discuss.elastic.co/u/Asa_Zalles-Milner)\
**Post date:** [August 14, 2019, 7:33pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/10 "2019-08-14T19:33:37Z")

</div>

> [@jbudz](#):
>
> Does the query work with just `env.overall:prod`

Work just fine.  
It is the ONLY "quoted string" searches that fail when a field is not specified.  
Since the use case is being able to find something in any field... that is what I'm trying to figure out why is not working.

---

<div class="post-metadata">

**Author:** ![Asa\_Zalles-Milner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asa_zalles-milner/32/43809_2.png) [@Asa\_Zalles-Milner](https://discuss.elastic.co/u/Asa_Zalles-Milner)\
**Post date:** [August 15, 2019, 2:41pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/11 "2019-08-15T14:41:55Z")

</div>

How would I go about reducing the mapping size?

---

<div class="post-metadata">

**Author:** ![Randy-312](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/randy-312/32/19451_2.png) [@Randy-312](https://discuss.elastic.co/u/Randy-312)\
**Post date:** [August 19, 2019, 2:35pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/12 "2019-08-19T14:35:36Z")

</div>

For me, this is occurring in 6.8.0, in the Management tab for Saved Objects, and Reporting.  
It doesn't appear to cause a problem, just an annoyance.

 ![KibanaFailedToLoadError](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4acd7b809007ad21f647219f30fbcb35fa1fb938.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2019, 2:35pm UTC](https://discuss.elastic.co/t/discover-request-timout-after-30000ms-mapping-size-is-larger-than-10mb-version-6-3-1/193863/13 "2019-09-16T14:35:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
