# Export has limited columns

**URL:** <https://discuss.elastic.co/t/export-has-limited-columns/285584>\
**Category:** Kibana\
**Created:** [September 30, 2021, 11:38am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584 "2021-09-30T11:38:25Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [September 30, 2021, 11:38am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/1 "2021-09-30T11:38:25Z")

</div>

Hello,

I hope this message finds the community members safe and healthy.

I'm having incomplete data when exporting via Kibana & the output is erratic.

**I am carrying out the searches on the same index**

1. Total documents found are **22,174** with 115 fields (columns) the export is correct and shows all columns and rows. Total export size is 11648162 bytes.
2. Total documents found are **3291** with 115 fields **but in this export only two fields are being exported.** Total export size is 63453 bytes. Only the `time and _source` columns are being exported. I am however able to see the data in discover tab.

In both the searches I get an warning: `Your CSV contains characters that spreadsheet applications might interpret as formulas. `

In both the searches there are no errors

```auto
"rawResponse": {
    "took": 1562,
    "timed_out": false,
    "_shards": {
      "total": 14,
      "successful": 14,
      "skipped": 0,
      "failed": 0

```

How could I diagnose this & get the full export.

There are total of 3 nodes in the cluster with 2 data nodes and 1 voting noted. Both the searches were exported via the second data node.

PS: If i combine the timeline I get an error during export : `Error: Max attempts reached (3). Queue timeout reached.`

Thank you very much

---

<div class="post-metadata">

**Author:** ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)\
**Post date:** [October 1, 2021, 9:53am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/2 "2021-10-01T09:53:01Z")

</div>

Hi 👋

a couple questions:

1. What Kibana version are you at?
2. What is the difference between two searches? Filters / time range?
3. Do you have any selected fields"in Discover for the 2nd search? If you do, then only selected fields with get into the report

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [October 1, 2021, 10:32am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/3 "2021-10-01T10:32:56Z")

</div>

Hello,

Thank you very much for replying.

1. Kibana version is 7.15 (entire Elastic stack is running 7.15)
2. Both searches are for 3 months period. (January to March end and April to June end) - April to June works perfect even though it has less documents for the search query.
3. No Specific fields are selected in the in discover tab.

Additional:

I downloaded all of the data for one day (around 300,000 entires) from search one and I only got the two columns. 😑

Is there other diagnostic log(s) that I can provide to check this further?

---

<div class="post-metadata">

**Author:** ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)\
**Post date:** [October 1, 2021, 10:41am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/4 "2021-10-01T10:41:06Z")

</div>

> [@parthmaniar](#):
>
> I downloaded all of the data for one day (around 300,000 entires) from search one and I only got the two columns.

Hm, do you see all the columns in discover for January to March data?

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [October 1, 2021, 10:42am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/5 "2021-10-01T10:42:20Z")

</div>

Yes Sir! I can also expand on them and carry out searches on keywords in that data.

---

<div class="post-metadata">

**Author:** ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)\
**Post date:** [October 1, 2021, 10:56am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/6 "2021-10-01T10:56:33Z")

</div>

Just to confirm this isn't a csv software issue (sorry, I have to ask :D) have you tried to open a raw csv in a simple file editor and confirm that data is indeed missing?

I'll check with the team if there are other ideas 🙂

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [October 1, 2021, 11:00am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/7 "2021-10-01T11:00:41Z")

</div>

Here is a test for January 2021

From 5th January 0000 HRS to 0005 HRS.

1. Total documents - **4,362**
2. Output from query explorer:

```auto
"rawResponse": {
    "took": 89,
    "timed_out": false,
    "_shards": {
      "total": 14,
      "successful": 14,
      "skipped": 12,
      "failed": 0

```

Export result: Succeeded with all document and columns. If I try anything over like for one hour which has ~50,000 documents or one day which has ~1,20,000 documents it fails with error `Error: Max attempts reached (3). Queue timeout reached.`

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [October 1, 2021, 11:01am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/8 "2021-10-01T11:01:04Z")

</div>

> [@dosant](#):
>
> onfirm this isn't a csv software issue (sorry, I have to ask :D) have you tried to

Yes yes I opened the files in notepad++ 🙂

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [October 1, 2021, 11:13am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/9 "2021-10-01T11:13:43Z")

</div>

I did a search for the month of January for a specific term and I got the data with columns.

Let me do more work on this and provide data to determine when it fails.

---

<div class="post-metadata">

**Author:** ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)\
**Post date:** [October 1, 2021, 11:56am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/10 "2021-10-01T11:56:34Z")

</div>

Could you try reloading the page just before generating the report?:

1. Set needed time range
2. Reload the page
3. When results are loaded: share -\> generate csv

It might be a client state bug ☹

These are steps to reproduce the bug:

How to reproduce:

- Install Kibana
- Install the sample `kibana_sample_data_logs` dataset
- Go in Discover, `kibana_sample_data_logs` index pattern
- Do not select any field
- Save it as `TEST`
- Go in `Share` / `Generate CSV` (A)
- Download the CSV: Contains Timestamp & the whole JSON source
- Save it as `TEST` again (without enabling create new...) without refreshing the page
- Go in `Share` / `Generate CSV` (B)
- Download the CSV: the source will be `-`

---

<div class="post-metadata">

**Author:** ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)\
**Post date:** [October 4, 2021, 9:03am UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/11 "2021-10-04T09:03:44Z")

</div>

We've opened a bug: [Overwriting a Saved Search introduces columns parameter with invalid values and affects CSV exports · Issue #113693 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/113693)

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [October 6, 2021, 4:08pm UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/12 "2021-10-06T16:08:21Z")

</div>

Hello, thank you very much for the updated. I wasn't able to reproduce it after I cleared the cache and even rebooted my laptop. If I do get the same error again, I will send logs.

Further, I do have Kibana logs enabled, should I send them to you or upload on the GitHub ticket?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2021, 4:08pm UTC](https://discuss.elastic.co/t/export-has-limited-columns/285584/13 "2021-11-03T16:08:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
