# FacetPhaseExecutionException with new Marvel installation

**URL:** <https://discuss.elastic.co/t/facetphaseexecutionexception-with-new-marvel-installation/20441>\
**Category:** Elasticsearch\
**Created:** [October 27, 2014, 12:17am UTC](https://discuss.elastic.co/t/facetphaseexecutionexception-with-new-marvel-installation/20441 "2014-10-27T00:17:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![simpsora](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simpsora/32/647_2.png) [@simpsora](https://discuss.elastic.co/u/simpsora)\
**Post date:** [October 27, 2014, 12:17am UTC](https://discuss.elastic.co/t/facetphaseexecutionexception-with-new-marvel-installation/20441/1 "2014-10-27T00:17:08Z")

</div>

I've got a brand-new Marvel installation, and am having some frustrating  
issues with it: on the overview screen, I am constantly getting errors like:  
× _Oops!_ FacetPhaseExecutionException[Facet [timestamp]: failed to find  
mapping for node.ip\_port.raw]

_Production cluster:_

- ElasticSearch 1.1.1
- Marvel 1.2.1
- Running in vSphere

_Monitoring cluster:_

- ElasticSearch 1.3.4
- Marvel 1.2.1
- Running in AWS

After installing the plugin and bouncing all nodes in both clusters, Marvel  
seems to be working -- an index has been created in the monitoring cluster (  
.marvel-2014.10.26), and I see thousands of documents in there. There are  
documents with the following types: cluster\_state, cluster\_stats,  
index\_stats, indices\_stats, node\_stats. So, it does seem that data is  
being shipped from the prod cluster to the monitoring cluster.

I've seen in the user group that other people have had similar issues.  
Some of those mention problems with the marvel index template. I don't  
seem to have any at all templates in my monitoring cluster:

$ curl -XGET localhost:9200/\_template/  
{}

I tried manually adding the default template (as described in  
[http://www.elasticsearch.org/guide/en/marvel/current/#config-marvel-indices](http://www.elasticsearch.org/guide/en/marvel/current/#config-marvel-indices)),  
but that didn't seem to have any effect.

So far, I've seen just two specific errors in Marvel:

- FacetPhaseExecutionException[Facet [timestamp]: failed to find mapping  
for node.ip\_port.raw]
- FacetPhaseExecutionException[Facet [timestamp]: failed to find mapping  
for index.raw]

I've also looked through the logs on both the production and monitoring  
clusters, and the only errors are in the monitoring cluster resulting from  
queries from the Marvel UI, like this:

[2014-10-27 11:08:13,427][DEBUG][action.search.type] [ip-10-4-1-187]  
[.marvel-2014.10.27][1], node[SR\_hriFmTCav-8ofbKU-8g], [R], s[STARTED]:  
Failed to execute [org.elasticsearch.action.search.SearchRequest@661dc47e]  
org.elasticsearch.search.SearchParseException: [.marvel-2014.10.27][1]:  
query[ConstantScore(BooleanFilter(+_:_ +cache(\_type:index\_stats) +cache(  
@timestamp:[1414367880000 TO 1414368540000])))],from[-1],size[10]: Parse  
Failure [Failed to parse source [{"size":10,"query":{"filtered":{"query":{  
"match\_all":{}},"filter":{"bool":{"must":[{"match\_all":{}},{"term":{"\_type":  
"index\_stats"}},{"range":{"@timestamp":{"from":"now-10m/m","to":"now/m"  
}}}]}}}},"facets":{"timestamp":{"terms\_stats":{"key\_field":"index.raw",  
"value\_field":"@timestamp","order":"term","size":2000}},  
"primaries.docs.count":{"terms\_stats":{"key\_field":"index.raw","value\_field"  
:"primaries.docs.count","order":"term","size":2000}},  
"primaries.indexing.index\_total":{"terms\_stats":{"key\_field":"index.raw",  
"value\_field":"primaries.indexing.index\_total","order":"term","size":2000}},  
"total.search.query\_total":{"terms\_stats":{"key\_field":"index.raw",  
"value\_field":"total.search.query\_total","order":"term","size":2000}},  
"total.merges.total\_size\_in\_bytes":{"terms\_stats":{"key\_field":"index.raw",  
"value\_field":"total.merges.total\_size\_in\_bytes","order":"term","size":2000  
}},"total.fielddata.memory\_size\_in\_bytes":{"terms\_stats":{"key\_field":  
"index.raw","value\_field":"total.fielddata.memory\_size\_in\_bytes","order":  
"term","size":2000}}}}]]  
at org.elasticsearch.search.SearchService.parseSource(SearchService.  
java:660)  
at org.elasticsearch.search.SearchService.createContext(  
SearchService.java:516)  
at org.elasticsearch.search.SearchService.createAndPutContext(  
SearchService.java:488)  
at org.elasticsearch.search.SearchService.executeQueryPhase(  
SearchService.java:257)  
at org.elasticsearch.search.action.SearchServiceTransportAction$5.  
call(SearchServiceTransportAction.java:206)  
at org.elasticsearch.search.action.SearchServiceTransportAction$5.  
call(SearchServiceTransportAction.java:203)  
at org.elasticsearch.search.action.SearchServiceTransportAction$23.  
run(SearchServiceTransportAction.java:517)  
at java.util.concurrent.ThreadPoolExecutor.runWorker(  
ThreadPoolExecutor.java:1145)  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(  
ThreadPoolExecutor.java:615)  
at java.lang.Thread.run(Thread.java:745)  
Caused by: org.elasticsearch.search.facet.FacetPhaseExecutionException:  
Facet [timestamp]: failed to find mapping for index.raw  
at org.elasticsearch.search.facet.termsstats.TermsStatsFacetParser.  
parse(TermsStatsFacetParser.java:126)  
at org.elasticsearch.search.facet.FacetParseElement.parse(  
FacetParseElement.java:93)  
at org.elasticsearch.search.SearchService.parseSource(SearchService.  
java:644)  
... 9 more  
[2014-10-27 11:08:13,427][DEBUG][action.search.type] [ip-10-4-1-187]  
All shards failed for phase: [query]

Both clusters use the same timezone and their clocks are synchronized via  
NTP.

Does anyone have any suggestions on what to do next? I've reinstalled the  
plugin across both clusters without any changes.

Thanks much,  
Ross

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/252b4546-c63e-4349-a140-c6250a213e27%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/252b4546-c63e-4349-a140-c6250a213e27%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:53am UTC](https://discuss.elastic.co/t/facetphaseexecutionexception-with-new-marvel-installation/20441/2 "2017-07-06T00:53:47Z")

</div>


