# In ElasticSearch version 7.14.2, the following query causes the estimated\_size of the request circuit breaker to keep increasing and will not decrease even after 1-2 days

**URL:** <https://discuss.elastic.co/t/in-elasticsearch-version-7-14-2-the-following-query-causes-the-estimated-size-of-the-request-circuit-breaker-to-keep-increasing-and-will-not-decrease-even-after-1-2-days/383288>\
**Category:** Elasticsearch\
**Created:** [November 7, 2025, 11:03am UTC](https://discuss.elastic.co/t/in-elasticsearch-version-7-14-2-the-following-query-causes-the-estimated-size-of-the-request-circuit-breaker-to-keep-increasing-and-will-not-decrease-even-after-1-2-days/383288 "2025-11-07T11:03:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dackh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dackh/32/145637_2.png) [@dackh](https://discuss.elastic.co/u/dackh)\
**Post date:** [November 7, 2025, 11:03am UTC](https://discuss.elastic.co/t/in-elasticsearch-version-7-14-2-the-following-query-causes-the-estimated-size-of-the-request-circuit-breaker-to-keep-increasing-and-will-not-decrease-even-after-1-2-days/383288/1 "2025-11-07T11:03:04Z")

</div>

This index has 2 million documents, each with approximately 300 fields. The query syntax is as follows:

```auto
GET /option_indicator/_search

{

  "profile": true,

  "_source": true,

  "track_total_hits": true,

  "size": 0,

  "aggs": {

    "group_by_chain": {

      "multi_terms": {

        "terms": [

          { "field": "sc_name" },

          { "field": "en_name" },

          { "field": "oi_day_chg" },

          { "field": "option_id" },

          { "field": "chg_ratio" },

          { "field": "ask_volume" },

          { "field": "bid_volume" },

          { "field": "oi_week_chg" }

        ],

        "size":20000

      },

      "aggs": {

        "top_option_list": {

          "top_hits": {

            "size": 1, 

            "sort": [{ "volume": { "order": "desc" } }],

             "_source": {

              "includes": ["option_id", "en_name","volume"] 

            }

          }

        }

      }

    }

  }

}

```

---

<div class="post-metadata">

**Author:** ![dackh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dackh/32/145637_2.png) [@dackh](https://discuss.elastic.co/u/dackh)\
**Post date:** [November 7, 2025, 11:05am UTC](https://discuss.elastic.co/t/in-elasticsearch-version-7-14-2-the-following-query-causes-the-estimated-size-of-the-request-circuit-breaker-to-keep-increasing-and-will-not-decrease-even-after-1-2-days/383288/2 "2025-11-07T11:05:05Z")

</div>

I tried other query syntaxes and didn't have this problem, such as aggregation with composite + source.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 7, 2025, 11:15am UTC](https://discuss.elastic.co/t/in-elasticsearch-version-7-14-2-the-following-query-causes-the-estimated-size-of-the-request-circuit-breaker-to-keep-increasing-and-will-not-decrease-even-after-1-2-days/383288/3 "2025-11-07T11:15:36Z")

</div>

The version of Elasticsearch you are running was released over 4 years ago and has been EOL and unsupported a long, long time. I would recommend upgrading to a recent and supported version, ideally the latest 9.x, and check whether the reported issue is still present there.

---

<div class="post-metadata">

**Author:** ![dackh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dackh/32/145637_2.png) [@dackh](https://discuss.elastic.co/u/dackh)\
**Post date:** [November 7, 2025, 11:20am UTC](https://discuss.elastic.co/t/in-elasticsearch-version-7-14-2-the-following-query-causes-the-estimated-size-of-the-request-circuit-breaker-to-keep-increasing-and-will-not-decrease-even-after-1-2-days/383288/4 "2025-11-07T11:20:56Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> The version of Elasticsearch you are running was released over 4 years ago and has been EOL and unsupported a long, long time. I would recommend upgrading to a recent and supported version, ideally the latest 9.x, and check whether the reported issue is still present there.

Could you please help confirm if this version contains this potential issue?

Many locations within our company likely use this version of the server. If the problem is confirmed, then we should inform everyone.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 7, 2025, 11:26am UTC](https://discuss.elastic.co/t/in-elasticsearch-version-7-14-2-the-following-query-causes-the-estimated-size-of-the-request-circuit-breaker-to-keep-increasing-and-will-not-decrease-even-after-1-2-days/383288/5 "2025-11-07T11:26:30Z")

</div>

I do unfortunately not have time to look through 4 years worth of potential issues and fixes or set up environments to try and recreate it. I would recommend you test it yourself with a new and supported version (ideally the latest) as I assume you know how to recreate the issue.

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [November 7, 2025, 3:02pm UTC](https://discuss.elastic.co/t/in-elasticsearch-version-7-14-2-the-following-query-causes-the-estimated-size-of-the-request-circuit-breaker-to-keep-increasing-and-will-not-decrease-even-after-1-2-days/383288/6 "2025-11-07T15:02:13Z")

</div>

> [@dackh](#):
>
> Many locations within our company likely use this version of the server. If the problem is confirmed, then we should inform everyone.

You should anyways inform them they are using an unsupported version from 4+ years ago? And also inform whichever team looks after these installations!?

---

<div class="post-metadata">

**Author:** ![dackh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dackh/32/145637_2.png) [@dackh](https://discuss.elastic.co/u/dackh)\
**Post date:** [November 10, 2025, 6:16am UTC](https://discuss.elastic.co/t/in-elasticsearch-version-7-14-2-the-following-query-causes-the-estimated-size-of-the-request-circuit-breaker-to-keep-increasing-and-will-not-decrease-even-after-1-2-days/383288/7 "2025-11-10T06:16:18Z")

</div>

@RainTown @Christian_Dahlqvist  
This issue should have been fixed by MR.

> <https://github.com/elastic/elasticsearch/pull/79422/files>
>
> The MultiTermsAggregator creates a BytesKeyedBucketOrds that never gets closed a…nd therefore it might leak the
> memory allocated into the circuit breaker.
> 
> backport #79362

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 10, 2025, 6:23am UTC](https://discuss.elastic.co/t/in-elasticsearch-version-7-14-2-the-following-query-causes-the-estimated-size-of-the-request-circuit-breaker-to-keep-increasing-and-will-not-decrease-even-after-1-2-days/383288/8 "2025-11-10T06:23:52Z")

</div>

That fix was included in Elasticsearch 7.15 so you will need to upgrade to get that. I would recommend upgrading to an as recent version as possible.
