# Illegal\_argument\_exception when trying to see Security/Hosts

**URL:** <https://discuss.elastic.co/t/illegal-argument-exception-when-trying-to-see-security-hosts/313140>\
**Category:** Elasticsearch\
**Created:** [August 29, 2022, 9:03am UTC](https://discuss.elastic.co/t/illegal-argument-exception-when-trying-to-see-security-hosts/313140 "2022-08-29T09:03:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [August 29, 2022, 9:03am UTC](https://discuss.elastic.co/t/illegal-argument-exception-when-trying-to-see-security-hosts/313140/1 "2022-08-29T09:03:42Z")

</div>

Hello!  
I am trying to see hosts on one of my clusters (self-hosted).  
I have got three nodes here.  
When I go to Security/Host I get error 400:  
 ![obraz](https://us1.discourse-cdn.com/elastic/original/3X/a/d/adf0dbb1eed0dd5e6b7da1c2c2bbae8fb6894973.png)  
Full error message:

```auto
{
  "message": "status_exception",
  "statusCode": 400,
  "attributes": {
    "type": "status_exception",
    "reason": "error while executing search",
    "caused_by": {
      "type": "search_phase_execution_exception",
      "reason": "all shards failed",
      "phase": "query",
      "grouped": true,
      "failed_shards": [
        {
          "shard": 0,
          "index": "filebeat-7.17.5-2022.08.29",
          "node": "CVsfpe93TZqMenYYAvjJvA",
          "reason": {
            "type": "illegal_argument_exception",
            "reason": "Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [host.name] in order to load field data by uninverting the inverted index. Note that this can use significant memory."
          }
        }
      ],
      "caused_by": {
        "type": "illegal_argument_exception",
        "reason": "Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [host.name] in order to load field data by uninverting the inverted index. Note that this can use significant memory.",
        "caused_by": {
          "type": "illegal_argument_exception",
          "reason": "Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [host.name] in order to load field data by uninverting the inverted index. Note that this can use significant memory."
        }
      }
    }
  }
}

```

I have created a new index pattern in Kibana:

 ![obraz](https://us1.discourse-cdn.com/elastic/original/3X/d/d/ddf86c6bb30a640ba7075ee9fe4d51da12ec3f8b.png)  
I search our forum but can't find similar problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2022, 9:04am UTC](https://discuss.elastic.co/t/illegal-argument-exception-when-trying-to-see-security-hosts/313140/2 "2022-09-26T09:04:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
