# ERROR: this cluster currently has \[x\]/\[x\] maximum normal shards open

**URL:** <https://discuss.elastic.co/t/error-this-cluster-currently-has-x-x-maximum-normal-shards-open/282254>\
**Category:** Elasticsearch\
**Created:** [August 23, 2021, 4:01pm UTC](https://discuss.elastic.co/t/error-this-cluster-currently-has-x-x-maximum-normal-shards-open/282254 "2021-08-23T16:01:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stef\_Nestor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stef_nestor/32/85483_2.png) [@Stef\_Nestor](https://discuss.elastic.co/u/Stef_Nestor)\
**Post date:** [August 23, 2021, 4:01pm UTC](https://discuss.elastic.co/t/error-this-cluster-currently-has-x-x-maximum-normal-shards-open/282254/1 "2021-08-23T16:01:06Z")

</div>

This example error may return from Elasticsearch to any ingestor (e.g. Logstash, Bulk, API, Beats, etc):

```diff
[{TIMESTAMP}][WARN][logstash.outputs.elasticsearch][x][y] Could not index event to Elasticsearch. {
	:status=> 400, 
	:action=> [ "index", {
		:_id=> "z", 
		:_index=> "x", 
		:routing=> nil, 
		:_type=> "_doc"
	}, #<LogStash::Event:#>], 
	:response=>{
		"index"=> { 
			"_index"=> "x", 
			"_type"=> "_doc", 
			"_id"=> "z", 
			"status"=> 400, 
			"error"=> { 
				"type"=> "illegal_argument_exception", 
- "reason"=> "Validation Failed: 1: this action would add [#] shards, but this cluster currently has [####]/[####] maximum normal shards open;" }}}}

```

---

<div class="post-metadata">

**Author:** ![Stef\_Nestor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stef_nestor/32/85483_2.png) [@Stef\_Nestor](https://discuss.elastic.co/u/Stef_Nestor)\
**Post date:** [August 23, 2021, 4:01pm UTC](https://discuss.elastic.co/t/error-this-cluster-currently-has-x-x-maximum-normal-shards-open/282254/2 "2021-08-23T16:01:14Z")

</div>

"_Maximum normal shards open_ " indicates that your target Elasticsearch cluster has hit its maximum shard limit as calculated by _[cluster.max\_shards\_per\_node](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-cluster.html#cluster-shard-limit) \* number\_of\_data\_nodes_ .

You may consider creating temporary breathing room for the cluster by [removing unused indices](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-delete-index.html) or (less recommended) short-term [overriding this setting](https://www.elastic.co/guide/en/elasticsearch/reference/7.13/cluster-update-settings.html#cluster-update-settings).

Once your cluster has breathing room, kindly note it sounds like its [oversharded](https://www.elastic.co/blog/managing-and-troubleshooting-elasticsearch-memory) and it may be time to scale out or use more [rigorous ILM](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2021, 4:02pm UTC](https://discuss.elastic.co/t/error-this-cluster-currently-has-x-x-maximum-normal-shards-open/282254/3 "2021-09-20T16:02:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
