# Export results from query that is more than the default maxClauseCount

**URL:** <https://discuss.elastic.co/t/export-results-from-query-that-is-more-than-the-default-maxclausecount/311925>\
**Category:** Elasticsearch\
**Created:** [August 11, 2022, 12:21pm UTC](https://discuss.elastic.co/t/export-results-from-query-that-is-more-than-the-default-maxclausecount/311925 "2022-08-11T12:21:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![xynobob](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xynobob/32/105064_2.png) [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Post date:** [August 11, 2022, 12:21pm UTC](https://discuss.elastic.co/t/export-results-from-query-that-is-more-than-the-default-maxclausecount/311925/1 "2022-08-11T12:21:05Z")

</div>

Hi,

I have this issue where for my needs, I am required to export **all** the rules from Elastic Security and keep it locally which I use this command to achieve it - `POST api/detection_engine/rules/_export`. However the main problem is that the rules I want to export amounts to 2000+ rules (and counting), more than the default limit of maxClauseCount of 1024, so I will tend to get this error below:

```auto
{"message":"all shards failed: search_phase_execution_exception: [query_shard_exception] Reason: failed to create query: maxClauseCount is set to 1024","status_code":400}

```

Is there any other workaround to query more than 1024 items without needing to change the maxClauseCount settings? This is because, even in the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/search-settings.html) it does not recommend changing the limit as it may degrade CPU and RAM performance, so I am trying my best to not go that route. Any pointers will be appreciated!

Also additional question, does the rules stored under an index? This is because I seems to not be able to find the index that stores the rules.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2022, 12:21pm UTC](https://discuss.elastic.co/t/export-results-from-query-that-is-more-than-the-default-maxclausecount/311925/2 "2022-09-08T12:21:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
