# Getting maxClauseCount error when using document-level security

**URL:** <https://discuss.elastic.co/t/getting-maxclausecount-error-when-using-document-level-security/73923>\
**Category:** Elasticsearch\
**Created:** [February 4, 2017, 12:31am UTC](https://discuss.elastic.co/t/getting-maxclausecount-error-when-using-document-level-security/73923 "2017-02-04T00:31:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmcginty](https://avatars.discourse-cdn.com/v4/letter/j/e9bcb4/32.png) [@jmcginty](https://discuss.elastic.co/u/jmcginty)\
**Post date:** [February 4, 2017, 12:31am UTC](https://discuss.elastic.co/t/getting-maxclausecount-error-when-using-document-level-security/73923/1 "2017-02-04T00:31:28Z")

</div>

We tag our documents with security ids and wish to filter the documents at query time with a list of security ids associated with the user.

We added a field to user.metadata called 'sids' which is an array of integers. Our document has a field called 'securityIds' that is an array of integers. We set up the role's query as follows:

```
   "query": {
      "template":{
           "inline": "{\"terms\" : { \"securityIds\" : {{#toJson}}_user.metadata.sids{{/toJson}} } }"
      }
    }

```

This works perfectly until we add more than 1024 sids to the user. At that point we get the following error:

caused by: too\_many\_clauses: maxClauseCount is set to 1024  
org.apache.lucene.search.BooleanQuery$Builder.add(BooleanQuery.java:136)  
org.elasticsearch.index.query.TermsQueryBuilder.handleTermsQuery(TermsQueryBuilder.java:450)  
org.elasticsearch.index.query.TermsQueryBuilder.doToQuery(TermsQueryBuilder.java:411)  
org.elasticsearch.index.query.AbstractQueryBuilder.toQuery(AbstractQueryBuilder.java:97)  
org.elasticsearch.index.query.QueryShardContext.lambda$toQuery$1(QueryShardContext.java:306)  
org.elasticsearch.index.query.QueryShardContext.toQuery(QueryShardContext.java:323)  
org.elasticsearch.index.query.QueryShardContext.toQuery(QueryShardContext.java:305)  
org.elasticsearch.xpack.security.authz.accesscontrol.SecurityIndexSearcherWrapper.wrap(SecurityIndexSearcherWrapper.java:176)  
org.elasticsearch.index.shard.IndexSearcherWrapper.wrap(IndexSearcherWrapper.java:75)

Note that if we implement this w/o xpack by passing in a filter list into the query containing the sid list, the queries work fine. But we were hoping that xpack would give us better performance than passing large fiters into every query.

Is there any way to accomplish this with xpack?

Also any thoughts you may have on the performance of xpack for this kind of usage would be greatly appreciated.

Thanks!

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [February 9, 2017, 8:19pm UTC](https://discuss.elastic.co/t/getting-maxclausecount-error-when-using-document-level-security/73923/2 "2017-02-09T20:19:16Z")

</div>

What is the relationship between the number of sids and documents?

> Note that if we implement this w/o xpack by passing in a filter list into the query containing the sid list, the queries work fine

To be clear, are you talking about something like:

```
{
  "query": { 
    "bool": { 
      "filter": [ 
        { "terms": { "securityIds": "..." }}
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![jmcginty](https://avatars.discourse-cdn.com/v4/letter/j/e9bcb4/32.png) [@jmcginty](https://discuss.elastic.co/u/jmcginty)\
**Post date:** [February 10, 2017, 1:10am UTC](https://discuss.elastic.co/t/getting-maxclausecount-error-when-using-document-level-security/73923/3 "2017-02-10T01:10:13Z")

</div>

Yes, exactly.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [February 10, 2017, 4:14pm UTC](https://discuss.elastic.co/t/getting-maxclausecount-error-when-using-document-level-security/73923/4 "2017-02-10T16:14:36Z")

</div>

Thanks for bringing this up; we're planning to fix this in our next minor release.

Regarding performance, I think it will depend on the relationship between security ids, documents, and users.

---

<div class="post-metadata">

**Author:** ![jmcginty](https://avatars.discourse-cdn.com/v4/letter/j/e9bcb4/32.png) [@jmcginty](https://discuss.elastic.co/u/jmcginty)\
**Post date:** [February 10, 2017, 4:55pm UTC](https://discuss.elastic.co/t/getting-maxclausecount-error-when-using-document-level-security/73923/5 "2017-02-10T16:55:12Z")

</div>

Great, thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2017, 4:55pm UTC](https://discuss.elastic.co/t/getting-maxclausecount-error-when-using-document-level-security/73923/6 "2017-03-10T16:55:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
