# ES|QL fails with 'Data too large message for a small dataset

**URL:** <https://discuss.elastic.co/t/es-ql-fails-with-data-too-large-message-for-a-small-dataset/376120>\
**Category:** Elasticsearch\
**Tags:** esql\
**Created:** [March 19, 2025, 1:27pm UTC](https://discuss.elastic.co/t/es-ql-fails-with-data-too-large-message-for-a-small-dataset/376120 "2025-03-19T13:27:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![GlebCA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glebca/32/78044_2.png) [@GlebCA](https://discuss.elastic.co/u/GlebCA)\
**Post date:** [March 19, 2025, 1:27pm UTC](https://discuss.elastic.co/t/es-ql-fails-with-data-too-large-message-for-a-small-dataset/376120/1 "2025-03-19T13:27:18Z")

</div>

I am running the following ES|QL query against 192M documents

```auto
from filebeat-audit-* 
| where user.name is not null AND source.ip is not null and host.name is not null 
| where event.outcome == "success" and cidr_match(source.ip,"2.56.0.0/16") 
| stats cnt = count_distinct(source.ip) by user.name 
| keep cnt, user.name 
| where cnt > 1
| limit 10000

```

and it returns error:  
`[esql] > Unexpected error from Elasticsearch: circuit_breaking_exception - [request] Data too large, data for [<reused_arrays>] would be [21654658976/20.1gb], which is larger than the limit of [18038862643/16.7gb]`

but if I remove **stats** - it returns only **305** documents (source.ip matches 2.56.0.0/16)... why Elastic cannot run stats on it?

```auto
from filebeat-audit-* 
| where user.name is not null AND source.ip is not null and host.name is not null 
| where event.outcome == "success" and cidr_match(source.ip,"2.56.0.0/16") 
| limit 10000

```

---

<div class="post-metadata">

**Author:** ![GlebCA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glebca/32/78044_2.png) [@GlebCA](https://discuss.elastic.co/u/GlebCA)\
**Post date:** [March 19, 2025, 2:49pm UTC](https://discuss.elastic.co/t/es-ql-fails-with-data-too-large-message-for-a-small-dataset/376120/2 "2025-03-19T14:49:30Z")

</div>

Found workaround - add an intermediate stat

```auto
from filebeat-audit-* 
| where user.name is not null and source.ip is not null and host.name is not null and event.outcome=="success" and cidr_match(source.ip,"2.56.0.0/16") 
| STATS SUM(1) BY user.name,source.ip 
| STATS cnt = count_distinct (source.ip) by user.name
| keep cnt, user.name
| WHERE cnt > 1 
| limit 10000

```

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 19, 2025, 10:03pm UTC](https://discuss.elastic.co/t/es-ql-fails-with-data-too-large-message-for-a-small-dataset/376120/3 "2025-03-19T22:03:21Z")

</div>

It's good that you found a workaround, but still the original q is interesting.

Would you/others consider it a bug? In your case the original ES|QL query failed, but had you had maybe less than 192M documents it might have "worked", but still consumed a lot of resources temporarily (and arguably un-necessarily).

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 20, 2025, 3:56am UTC](https://discuss.elastic.co/t/es-ql-fails-with-data-too-large-message-for-a-small-dataset/376120/4 "2025-03-20T03:56:16Z")

</div>

What version?

---

<div class="post-metadata">

**Author:** ![GlebCA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glebca/32/78044_2.png) [@GlebCA](https://discuss.elastic.co/u/GlebCA)\
**Post date:** [March 20, 2025, 2:29pm UTC](https://discuss.elastic.co/t/es-ql-fails-with-data-too-large-message-for-a-small-dataset/376120/5 "2025-03-20T14:29:33Z")

</div>

Elastic 8.15.5

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 20, 2025, 5:24pm UTC](https://discuss.elastic.co/t/es-ql-fails-with-data-too-large-message-for-a-small-dataset/376120/6 "2025-03-20T17:24:33Z")

</div>

Could you try 8.17.3?

There may have been some issues with memory and ESQL in that version but I can not readily find it.
