# Error since 7.4 upgrade - field expansion matches too many fields

**URL:** https://discuss.elastic.co/t/error-since-7-4-upgrade-field-expansion-matches-too-many-fields/204087
**Category:** Elasticsearch
**Created:** [October 17, 2019, 3:18pm UTC](https://discuss.elastic.co/t/error-since-7-4-upgrade-field-expansion-matches-too-many-fields/204087 "2019-10-17T15:18:26Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![L33T](https://avatars.discourse-cdn.com/v4/letter/l/dbc845/32.png) [@L33T](https://discuss.elastic.co/u/L33T)
#### Post date: [October 17, 2019, 3:18pm UTC](https://discuss.elastic.co/t/error-since-7-4-upgrade-field-expansion-matches-too-many-fields/204087/1 "2019-10-17T15:18:27Z")

</div>

Hi,

Whenever i view any of my dashboards i get the below... How can i debug this?

{  
"took": 48,  
"timed\_out": false,  
"\_shards": {  
"total": 188,  
"successful": 187,  
"skipped": 172,  
"failed": 1,  
"failures": [  
{  
"shard": 0,  
"index": "winlogbeat-7.4.0-2019.10.17-000001",  
"node": "E6igdheIRFKMNeTpM2tbLA",  
"reason": {  
"type": "query\_shard\_exception",  
"reason": "failed to create query: {\n "bool" : {\n "must" : [\n {\n "query\_string" : {\n "query" : "_",\n "default\_field" : "_",\n "fields" : ,\n "type" : "best\_fields",\n "default\_operator" : "or",\n "max\_determinized\_states" : 10000,\n "enable\_position\_increments" : true,\n "fuzziness" : "AUTO",\n "fuzzy\_prefix\_length" : 0,\n "fuzzy\_max\_expansions" : 50,\n "phrase\_slop" : 0,\n "analyze\_wildcard" : true,\n "time\_zone" : "Europe/London",\n "escape" : false,\n "auto\_generate\_synonyms\_phrase\_query" : true,\n "fuzzy\_transpositions" : true,\n "boost" : 1.0\n }\n }\n],\n "filter" : [\n {\n "match\_all" : {\n "boost" : 1.0\n }\n },\n {\n "match\_phrase" : {\n "log.level" : {\n "query" : "error",\n "slop" : 0,\n "zero\_terms\_query" : "NONE",\n "boost" : 1.0\n }\n }\n },\n {\n "range" : {\n "@timestamp" : {\n "from" : "2019-10-16T23:00:00.000Z",\n "to" : "2019-10-17T22:59:59.999Z",\n "include\_lower" : true,\n "include\_upper" : true,\n "format" : "strict\_date\_optional\_time",\n "boost" : 1.0\n }\n }\n }\n],\n "adjust\_pure\_negative" : true,\n "boost" : 1.0\n }\n}",  
"index\_uuid": "DtneUPg9QgCN68P2NkDxSA",  
"index": "winlogbeat-7.4.0-2019.10.17-000001",  
"caused\_by": {  
"type": "illegal\_argument\_exception",  
"reason": "field expansion matches too many fields, limit: 1024, got: 1475"  
}  
}  
}  
]  
},

Cheers,

---

<div class="post-metadata">

### Author: ![cbuescher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cbuescher/32/60402_2.png) [@cbuescher](https://discuss.elastic.co/u/cbuescher)
#### Post date: [October 21, 2019, 1:47pm UTC](https://discuss.elastic.co/t/error-since-7-4-upgrade-field-expansion-matches-too-many-fields/204087/2 "2019-10-21T13:47:22Z")

</div>

> [@L33T](#):
>
> field expansion matches too many fields, limit: 1024, got: 1475

The number of fields a query can target is by default limited to 1024 by the the [`indices.query.bool.max_clause_count`](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-settings.html) setting. It is intended to protect users from accidentally running a query on too many fields (like 1475 in your case) because this typically is not done on purpose but rather by undespecifying the query, and can cause long running, expensive queries. In your case not specifying any "fields" will run the query on all fields. The question is whether this in inteded and/or avoidable. If you do this on purpose in your Kibana visualizations and cannot reduce the query to certain fields you need to update the setting to accomodate for the number of fields you have. More than 1000 fields in an index is remarkably high though and you might want to spent some time asking yourself what all these fields are doing there (or if some of them were e.g. created by accident using dynamic mapping etc...)

Cheers

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 18, 2019, 1:47pm UTC](https://discuss.elastic.co/t/error-since-7-4-upgrade-field-expansion-matches-too-many-fields/204087/3 "2019-11-18T13:47:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
