# Failing shard with illegal\_argument\_exception

**URL:** <https://discuss.elastic.co/t/failing-shard-with-illegal-argument-exception/292977>\
**Category:** Elasticsearch\
**Created:** [December 27, 2021, 1:47pm UTC](https://discuss.elastic.co/t/failing-shard-with-illegal-argument-exception/292977 "2021-12-27T13:47:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![obol89](https://avatars.discourse-cdn.com/v4/letter/o/f0a364/32.png) [@obol89](https://discuss.elastic.co/u/obol89)\
**Post date:** [December 27, 2021, 1:47pm UTC](https://discuss.elastic.co/t/failing-shard-with-illegal-argument-exception/292977/1 "2021-12-27T13:47:46Z")

</div>

Hi Everyone,

When I'm trying to filter some data in Kibana I'm getting this message "1 of 716 shards failed" with this explanation:

```auto
illegal_argument_exception at shard 0 
index metricbeat-7.15.0-2021.12.27
node bfnMWOKoTsikcLiPsxSAcw

```

There is also longer explanation like that:  
_"Reason_

_Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [host.hostname] in order to load field data by uninverting the inverted index. Note that this can use significant memory."_

This is my **Request** :

> **[request - Pastebin.com](https://pastebin.com/Pxdwgfc6)**
>
> Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.

and **Response** :

> **[response - Pastebin.com](https://pastebin.com/DgXiiV2U)**
>
> Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.

When I will look at this index it looks like that:

> **[index - Pastebin.com](https://pastebin.com/sHkep2M0)**
>
> Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.

Thank you for any help and hints in advance.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [December 27, 2021, 2:53pm UTC](https://discuss.elastic.co/t/failing-shard-with-illegal-argument-exception/292977/2 "2021-12-27T14:53:59Z")

</div>

Hi @obol89

reason for the failure is that type of the field "host.name" on the index is "text" type and the query requires terms aggregation on that field. I suppose the mappings is different from other successful indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2022, 2:54pm UTC](https://discuss.elastic.co/t/failing-shard-with-illegal-argument-exception/292977/3 "2022-01-24T14:54:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
