I'm trying to come up with a good solution to what I would think is a common problem. Currently managing a cluster over 1PB of data, when a user logs in they get the default discovery page which runs the query to search ALL logs over the last 1 minute. Now, there is training around teaching users to use filters and how to write a performant query. But, you are always going to have those users that want all the logs "*" since the beginning of time. Now, in this case, Kibana timeout like it should, and the query is eventually canceled, but this logs a 500 error and just in general isn't a great user experience to get a big red banner claiming a "Gateway timeout" So, I was wondering if anyone has any good ideas on how to encourage better behavior via a technological implementation? Once users have filters there isn't much issue across searching from the start of time, and that is a valid use case. So, i'm just looking for ideas here.