# Increase max\_bucket to 60,000 or make 6 msearch returning 10,000 buckets each?

**URL:** <https://discuss.elastic.co/t/increase-max-bucket-to-60-000-or-make-6-msearch-returning-10-000-buckets-each/306480>\
**Category:** Elasticsearch\
**Created:** [June 6, 2022, 4:17pm UTC](https://discuss.elastic.co/t/increase-max-bucket-to-60-000-or-make-6-msearch-returning-10-000-buckets-each/306480 "2022-06-06T16:17:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![misterone](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@misterone](https://discuss.elastic.co/u/misterone)\
**Post date:** [June 6, 2022, 4:17pm UTC](https://discuss.elastic.co/t/increase-max-bucket-to-60-000-or-make-6-msearch-returning-10-000-buckets-each/306480/1 "2022-06-06T16:17:20Z")

</div>

hey, I have a query that does this. It's a bunch of terms aggregations. (group by = terms)

```auto
filter by date from year 2015 to 2020
  group by region
    group by date from year 2015 to 2020
    group by country
      group by date from year 2015 to 2020
      group by city
        group by date from year 2015 to 2020
          group by sales name
            group by date from year 2015 to 2020

```

the output looks like this. These are the sales broken down by region, country, person and year :

```auto
Region Country City Name 2O15 2016 2017 2018 2019 2020
America 4000 8000 4000 6000 2000 4000
                
                United States 2000 4000 2000 3000 1000 2000     
                                
                                New York 1000 2000 1000 1500 500 1000     
                                            
                                            James 500 1000 500 750 250 500     
                                            
                                            John 500 1000 500 750 250 500     

                                Los Angeles 1000 2000 1000 1500 500 1000     
                                            
                                            James 500 1000 500 750 250 500     
                                            
                                            John 500 1000 500 750 250 500 
                
                Mexico 2000 4000 2000 3000 1000 2000     
                                
                                Mexico 1000 2000 1000 1500 500 1000     
                                            
                                            James 500 1000 500 750 250 500     
                                            
                                            John 500 1000 500 750 250 500     

                                guadalajara 1000 2000 1000 1500 500 1000     
                                            
                                            James 500 1000 500 750 250 500     
                                            
                                            John 500 1000 500 750 250 500 

```

**Problem : I hit a max\_bucket limit because the limit is 10,000, it turns out I need 60,000 buckets.**  
Details :

- this requirement is non negotiable. It has to be returned like this
- I tried to limit requirements to only load one level at a time, but we have a download button where we have to retrieve the whole data anyway.
- it's not cachable unfortunately, because this report depends on p parameters that can each have n values. caching it would mean we cache more than 1000 variations.

So right now I see two options :

- increase max\_buckets to 60000.
- query the tree step by step in an msearch.

Here are the pros and cons for each options

- 1 big query that returns 60,000 buckets:
  - Pro :
    - simpler

  - Con :
    - higher payload

- 6 small queries that each return 10,000 buckets ?
  - Pro :
    - smaller payload because less buckets

  - Con :
    - The backend will have to rebuild the tree from each msearch result of 10,000 buckets, and I am wondering if Elasticsearch is not better at doing this on its own.
    - More complex

1. Do you have a pro / con to add ?
2. Which option do you recommend ?
3. Do you recommend other options ?

---

<div class="post-metadata">

**Author:** ![Ignacio\_Vera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ignacio_vera/32/36674_2.png) [@Ignacio\_Vera](https://discuss.elastic.co/u/Ignacio_Vera)\
**Post date:** [June 8, 2022, 10:50am UTC](https://discuss.elastic.co/t/increase-max-bucket-to-60-000-or-make-6-msearch-returning-10-000-buckets-each/306480/2 "2022-06-08T10:50:55Z")

</div>

This issue tells me you are running a very old version. The max bucket limit was increase to 65535 in Elasticsearch 7.9 ([Increase search.max\_buckets to 65,535 by imotov · Pull Request #57042 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/pull/57042)).

My recommendation is to upgrade so this is not an issue for you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2022, 10:50am UTC](https://discuss.elastic.co/t/increase-max-bucket-to-60-000-or-make-6-msearch-returning-10-000-buckets-each/306480/3 "2022-06-08T10:50:55Z")

</div>

Elasticsearch 7.9 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2022, 10:51am UTC](https://discuss.elastic.co/t/increase-max-bucket-to-60-000-or-make-6-msearch-returning-10-000-buckets-each/306480/4 "2022-07-06T10:51:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
