# Increasing max\_buckets for specific Visualizations

**URL:** <https://discuss.elastic.co/t/increasing-max-buckets-for-specific-visualizations/187390>\
**Category:** Kibana\
**Created:** [June 25, 2019, 4:49pm UTC](https://discuss.elastic.co/t/increasing-max-buckets-for-specific-visualizations/187390 "2019-06-25T16:49:22Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhil04](https://avatars.discourse-cdn.com/v4/letter/n/df705f/32.png) [@Nikhil04](https://discuss.elastic.co/u/Nikhil04)\
**Post date:** [June 25, 2019, 4:49pm UTC](https://discuss.elastic.co/t/increasing-max-buckets-for-specific-visualizations/187390/1 "2019-06-25T16:49:22Z")

</div>

Hi,

Today we ran into an error when viewing a Visualization for a period of 24 hrs.Error Said "Courier fetch: 1 out of 8 shards failed".

On deeper inspection, we found that the query for Visualization gave error for max\_buckets.Our setting for max\_buckets is 10000 and the query is failing because it needs more buckets.When we increased the bucket size to 20000, the query and Visualization are running fine for a period of 24hrs.

max\_buckets is a cluster level setting and we don't want to keep it 20000 for the entire cluster but we want to keep it only for that particular Visualization. Is this possible?

Thanks and Regards,  
Nikhil

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [June 25, 2019, 11:00pm UTC](https://discuss.elastic.co/t/increasing-max-buckets-for-specific-visualizations/187390/2 "2019-06-25T23:00:34Z")

</div>

Unfortunately, the max\_buckets setting is only available at the cluster level settings. So what you're asking is not possible. You would have to change the cluster settings to load the visualization.

```auto
PUT _cluster/settings
{
  "transient": {
    "search.max_buckets": 20000
  }
}

```

---

<div class="post-metadata">

**Author:** ![Nikhil04](https://avatars.discourse-cdn.com/v4/letter/n/df705f/32.png) [@Nikhil04](https://discuss.elastic.co/u/Nikhil04)\
**Post date:** [June 26, 2019, 7:33am UTC](https://discuss.elastic.co/t/increasing-max-buckets-for-specific-visualizations/187390/3 "2019-06-26T07:33:41Z")

</div>

Hi @nickpeihl,

Thank you for the update!

Could you have any more details on max\_bucket settings like, What may be the impact of increasing it? How much I can increase it to without impacting elasticsearch?

We have set it to 10000 to prevent killer queries being executed on elasticsearch but we have not found what can be the optimal value for max\_bucket for our cluster.

Also, I would like to know whether there is any auditing which will help to find out whether there was any modification to any Visualization by users.Any view on this would be very helpful

Thanks,  
Nikhil

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [June 26, 2019, 3:40pm UTC](https://discuss.elastic.co/t/increasing-max-buckets-for-specific-visualizations/187390/4 "2019-06-26T15:40:04Z")

</div>

Elasticsearch sets a default limit of 10000 for the `search.max_buckets` setting. This can be changed, but it can also have a detrimental effect on the cluster, as you say if someone sends "killer queries".

Kibana has a default limit of 2000 for the max buckets in the Advanced Settings under Management. This is a conservative limit and can be set higher. But passing a lot of data around in the browser can be extremely resource intensive and cause browser hangups.

Perhaps we should try to optimize your visualization rather than change cluster settings. Which visualization are you using that needs so many buckets? Does it make sense to visualize that much data at one time? There is a limit to how much detail human eye can perceive.

---

<div class="post-metadata">

**Author:** ![Nikhil04](https://avatars.discourse-cdn.com/v4/letter/n/df705f/32.png) [@Nikhil04](https://discuss.elastic.co/u/Nikhil04)\
**Post date:** [June 27, 2019, 4:35pm UTC](https://discuss.elastic.co/t/increasing-max-buckets-for-specific-visualizations/187390/5 "2019-06-27T16:35:38Z")

</div>

Hi @nickpeihl,

We have stuck to 10000 max\_buckets and won't be changing any cluster settings that would affect the cluster.

I had one idea, please let me know would it make any difference?

Visualization is run for the period of 24 hours on one index doing many aggregations. Is it possible, If i reindex the original index(1 shard 1 replica) into a new index(taking only the fields i need for aggregation) and change the shard settings of new index to 1 shared and 3 replica, would it by any chance take less buckets for the period of 24 hours?

ES cluster consists of 3 nodes (master+data).

Thanks

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [July 1, 2019, 11:54pm UTC](https://discuss.elastic.co/t/increasing-max-buckets-for-specific-visualizations/187390/6 "2019-07-01T23:54:39Z")

</div>

Anything you can do to limit the granularity of the data you are querying may help. Your idea sounds similar to the new rollup indices feature in Elasticsearch. I wonder if that feature would help you?

> **[How to Create, Manage, and Visualize Elasticsearch Rollup Data in Kibana](https://www.elastic.co/blog/how-to-create-manage-and-visualize-elasticsearch-rollup-data-in-kibana)**
>
> Learn how to save space by rolling up historical Elasticsearch data into summary documents that you can create, manage, and visualize with new tools in Kibana.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/xpack-rollup.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/xpack-rollup.html)

---

<div class="post-metadata">

**Author:** ![Nikhil04](https://avatars.discourse-cdn.com/v4/letter/n/df705f/32.png) [@Nikhil04](https://discuss.elastic.co/u/Nikhil04)\
**Post date:** [July 2, 2019, 5:02pm UTC](https://discuss.elastic.co/t/increasing-max-buckets-for-specific-visualizations/187390/7 "2019-07-02T17:02:55Z")

</div>

Hey @nickpeihl,

We did the reindex part that I mentioned earlier but I didn't work since the data returned and the aggregations remain same.

We are also checking the rollup index feature but it seems in v6.3 visualization on rollup index is not there, let me check more and get back

Thank you for your help and suggestions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2019, 5:03pm UTC](https://discuss.elastic.co/t/increasing-max-buckets-for-specific-visualizations/187390/8 "2019-07-30T17:03:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
