# Hard Limit on Kibana Elasticsearch SQL?

**URL:** <https://discuss.elastic.co/t/hard-limit-on-kibana-elasticsearch-sql/172406>\
**Category:** Kibana\
**Tags:** elastic-stack-sql\
**Created:** [March 14, 2019, 6:48pm UTC](https://discuss.elastic.co/t/hard-limit-on-kibana-elasticsearch-sql/172406 "2019-03-14T18:48:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rudyamid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rudyamid/32/38393_2.png) [@rudyamid](https://discuss.elastic.co/u/rudyamid)\
**Post date:** [March 14, 2019, 6:48pm UTC](https://discuss.elastic.co/t/hard-limit-on-kibana-elasticsearch-sql/172406/1 "2019-03-14T18:48:03Z")

</div>

I use this Elasticsearch SQL Query from Kibana's Canvas and I hit a hard limit of 1000 results returned every time.

SELECT Severity FROM "fwlogs-zayofw\*" WHERE Severity LIKE '%medium%' AND ThreatName.keyword IS NOT NULL

I even tried adding "limit ALL" at the end of it, and it will still return 1000 results. Anyone know how to get around this, or is the limit there by design?

regards  
Rudy

---

<div class="post-metadata">

**Author:** ![cufflinks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cufflinks/32/42129_2.png) [@cufflinks](https://discuss.elastic.co/u/cufflinks)\
**Post date:** [March 14, 2019, 7:41pm UTC](https://discuss.elastic.co/t/hard-limit-on-kibana-elasticsearch-sql/172406/2 "2019-03-14T19:41:41Z")

</div>

Hi Rudyamid,

The default is set to 1000 but you can override that in your ES SQL function using the `count` argument.

Something like:  
`essql query="..." count=10000`

---

<div class="post-metadata">

**Author:** ![rudyamid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rudyamid/32/38393_2.png) [@rudyamid](https://discuss.elastic.co/u/rudyamid)\
**Post date:** [March 14, 2019, 8:21pm UTC](https://discuss.elastic.co/t/hard-limit-on-kibana-elasticsearch-sql/172406/3 "2019-03-14T20:21:13Z")

</div>

Hi John,

How do you specify the count=10000 setting in Kibana's Canvas interface? I can only type in the ES SQL query, but not specify any other setting outside of it.

---

<div class="post-metadata">

**Author:** ![cufflinks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cufflinks/32/42129_2.png) [@cufflinks](https://discuss.elastic.co/u/cufflinks)\
**Post date:** [March 14, 2019, 10:20pm UTC](https://discuss.elastic.co/t/hard-limit-on-kibana-elasticsearch-sql/172406/4 "2019-03-14T22:20:49Z")

</div>

You can check the UI by selecting an element, selecting the Data tab on the sidebar, and checking the existing config. There should be an option like count, size input or limit. If you don't see that, let me know what you see.

---

<div class="post-metadata">

**Author:** ![rudyamid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rudyamid/32/38393_2.png) [@rudyamid](https://discuss.elastic.co/u/rudyamid)\
**Post date:** [March 14, 2019, 10:37pm UTC](https://discuss.elastic.co/t/hard-limit-on-kibana-elasticsearch-sql/172406/5 "2019-03-14T22:37:38Z")

</div>

Ok, I see where you can edit it in the Expression Editor option on bottom right. However, adding the count=15000 gives me this error now. So it looks 10000 is the hard limit?

(and) [query\_phase\_execution\_exception] Batch size is too large, size must be less than or equal to: [10000] but was [15000]. Scroll batch sizes cost as much memory as result windows so they are controlled by the [index.max\_result\_window] index level setting. (and) [query\_phase\_execution\_exception] Batch size is too large, size must be less than or equal to: [10000] but was [15000]. Scroll batch sizes cost as much memory as result windows so they are controlled by the [index.max\_result\_window] index level setting.

---

<div class="post-metadata">

**Author:** ![cufflinks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cufflinks/32/42129_2.png) [@cufflinks](https://discuss.elastic.co/u/cufflinks)\
**Post date:** [March 14, 2019, 10:50pm UTC](https://discuss.elastic.co/t/hard-limit-on-kibana-elasticsearch-sql/172406/6 "2019-03-14T22:50:18Z")

</div>

I think you are correct. Seem seems like 10000 is the hard limit.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2019, 10:50pm UTC](https://discuss.elastic.co/t/hard-limit-on-kibana-elasticsearch-sql/172406/7 "2019-04-11T22:50:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
