# Inconsistency in data table and serach results and getting error

**URL:** <https://discuss.elastic.co/t/inconsistency-in-data-table-and-serach-results-and-getting-error/296446>\
**Category:** Kibana\
**Created:** [February 7, 2022, 9:37am UTC](https://discuss.elastic.co/t/inconsistency-in-data-table-and-serach-results-and-getting-error/296446 "2022-02-07T09:37:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mangeshs](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Post date:** [February 7, 2022, 9:37am UTC](https://discuss.elastic.co/t/inconsistency-in-data-table-and-serach-results-and-getting-error/296446/1 "2022-02-07T09:37:52Z")

</div>

I want to download the search results from dashboard but our kibana doesn't have that option. So I created data table as same search results. But data table showing less results than the search results so I increased the order size in split rows for the fields so I ma getting error

```auto
[esaggs] > Request to Elasticsearch failed: {
   "error":{
      "root_cause":[
         {
            "type":"too_many_buckets_exception",
            "reason":"Trying to create too many buckets. Must be less than or equal to: [10000] but was [10001]. This limit can be set by changing the [search.max_buckets] cluster level setting.",
            "max_buckets":10000
         }
      ],
      "type":"search_phase_execution_exception",
      "reason":"all shards failed",
      "phase":"query",
      "grouped":true,
      "failed_shards":[
         {
            "shard":0,
            "index":"events",
            "node":"pdKx6ekIQAaOLyCZrq_Fbw",
            "reason":{
               "type":"too_many_buckets_exception",
               "reason":"Trying to create too many buckets. Must be less than or equal to: [10000] but was [10001]. This limit can be set by changing the [search.max_buckets] cluster level setting.",
               "max_buckets":10000
            }
         }
      ]
   },
   "status":503
}

```

---

<div class="post-metadata">

**Author:** ![Marta\_Bondyra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_bondyra/32/102122_2.png) [@Marta\_Bondyra](https://discuss.elastic.co/u/Marta_Bondyra)\
**Post date:** [February 23, 2022, 9:05am UTC](https://discuss.elastic.co/t/inconsistency-in-data-table-and-serach-results-and-getting-error/296446/2 "2022-02-23T09:05:44Z")

</div>

if you are using TSVB, change your interval from 'auto' to something bigger, for example 1d (depends on how big is your timerange). The reason for this error is that there's too many time buckets to process for Elasticsearch. By changing the interval, you would limit the number of buckets and get less precise data, but calculable.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2022, 9:06am UTC](https://discuss.elastic.co/t/inconsistency-in-data-table-and-serach-results-and-getting-error/296446/3 "2022-03-23T09:06:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
