# Illegal\_argument\_exception when opening dashboard

**URL:** <https://discuss.elastic.co/t/illegal-argument-exception-when-opening-dashboard/295270>\
**Category:** Kibana\
**Created:** [January 24, 2022, 6:14pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-when-opening-dashboard/295270 "2022-01-24T18:14:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![yelloyonder](https://avatars.discourse-cdn.com/v4/letter/y/5fc32e/32.png) [@yelloyonder](https://discuss.elastic.co/u/yelloyonder)\
**Post date:** [January 24, 2022, 6:14pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-when-opening-dashboard/295270/1 "2022-01-24T18:14:59Z")

</div>

For ref we're using Elastic Cloud.

When opening a particular dashboard we see a shard failure. The error reason is:

> Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [log.level] in order to load field data by uninverting the inverted index. Note that this can use significant memory.

There are a couple of things that I don't fully understand

1. The shard error references an Index that isn't used by the Dashboard, so why is it complaining? I have dashboards that _do_ use the index referenced and they work fine.
2. If I check the mapping type for `log.level` in the referenced index:

```auto
  "log": {
          "properties": {
            "level": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword"
                }

```

It is type text but also has a keyword, so looks like there shouldn't be an issue?

Any tips would be greatly appreciated. I could change the type to 'keyword' but just wanted to understand why this is happening.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 25, 2022, 3:27am UTC](https://discuss.elastic.co/t/illegal-argument-exception-when-opening-dashboard/295270/2 "2022-01-25T03:27:50Z")

</div>

You need to be using `log.level.keyword` in instances like this, as fields mapped as a `keyword` are best for aggregations.

---

<div class="post-metadata">

**Author:** ![yelloyonder](https://avatars.discourse-cdn.com/v4/letter/y/5fc32e/32.png) [@yelloyonder](https://discuss.elastic.co/u/yelloyonder)\
**Post date:** [February 2, 2022, 3:03pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-when-opening-dashboard/295270/3 "2022-02-02T15:03:58Z")

</div>

Hi Mark, Thanks for the info, somehow I missed your comment. I created a new dashboard and the issue no longer occurs.

Cheers,  
Jon

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2022, 3:04pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-when-opening-dashboard/295270/4 "2022-03-02T15:04:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
