# Indices Stack Monitoring - Cannot expand \`inner\_hits\` for collapse field \`index\_stats.index\`

**URL:** <https://discuss.elastic.co/t/indices-stack-monitoring-cannot-expand-inner-hits-for-collapse-field-index-stats-index/386205>\
**Category:** Elastic Agent\
**Tags:** elastic-stack-monitoring, integrations\
**Created:** [May 7, 2026, 10:00am UTC](https://discuss.elastic.co/t/indices-stack-monitoring-cannot-expand-inner-hits-for-collapse-field-index-stats-index/386205 "2026-05-07T10:00:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![adminunix](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@adminunix](https://discuss.elastic.co/u/adminunix)\
**Post date:** [May 7, 2026, 10:00am UTC](https://discuss.elastic.co/t/indices-stack-monitoring-cannot-expand-inner-hits-for-collapse-field-index-stats-index/386205/1 "2026-05-07T10:00:49Z")

</div>

Hello,  
We have updated to Elasticsearch 9.4.0, Kibana 9.4.0, Elastic Agent 9.4.0 and Elasticsearch monitoring integration 1.20.2.  
Since then, the Stack Monitong Indices tab is broken and does not load the dashboard:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d49285dbd8ce754ce9c1dc0f875a88b04234529.png)

The error message is:

> [search\_phase\_execution\_exception Caused by: illegal\_argument\_exception: cannot expand `inner_hits` for collapse field `index_stats.index`, only indexed field can retrieve `inner_hits` Root causes: illegal\_argument\_exception: cannot expand `inner_hits` for collapse field `index_stats.index`, only indexed field can retrieve `inner_hits`: search\_phase\_execution\_exception Caused by: illegal\_argument\_exception: cannot expand `inner_hits` for collapse field `index_stats.index`, only indexed field can retrieve `inner_hits` Root causes: illegal\_argument\_exception: cannot expand `inner_hits` for collapse field `index_stats.index`, only indexed field can retrieve `inner_hits`]: all shards failed

My research suggests that this error may be because field **index\_stats.index** is an alias to field **elasticsearch.index.name** in data\_stream **metrics-elasticsearch.stack\_monitoring.index-default**.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/6/e6f6aa6eea2083fe2f54e80e01ae477205e3c151.png)

Kibana uses `collapse+inner_hits` and Elasticsearch doesn't support this for an alias field. Is this correct?

---

<div class="post-metadata">

**Author:** ![adminunix](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@adminunix](https://discuss.elastic.co/u/adminunix)\
**Post date:** [May 13, 2026, 11:47am UTC](https://discuss.elastic.co/t/indices-stack-monitoring-cannot-expand-inner-hits-for-collapse-field-index-stats-index/386205/2 "2026-05-13T11:47:50Z")

</div>

Does nobody else have this error?

---

<div class="post-metadata">

**Author:** ![adminunix](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@adminunix](https://discuss.elastic.co/u/adminunix)\
**Post date:** [May 19, 2026, 2:39pm UTC](https://discuss.elastic.co/t/indices-stack-monitoring-cannot-expand-inner-hits-for-collapse-field-index-stats-index/386205/3 "2026-05-19T14:39:55Z")

</div>

I solved the issue after asked an IA tool.

1. Create a component template for **metrics-elasticsearch.stack\_monitoring.index**

```auto
PUT _component_template/metrics-elasticsearch.stack_monitoring.index@custom
{
  "template": {
    "mappings": {
      "properties": {
        "elasticsearch": {
          "properties": {
            "index": {
              "properties": {
                "name": {
                  "type": "keyword",
                  "index": true,
                  "time_series_dimension": true
                }
              }
            }
          }
        }
      }
    }
  }
}

```

1. Delete data\_stream **metrics-elasticsearch.stack\_monitoring.index-default**

2. A new data\_stream and a backing index is generated automatically with correct mapping **"index": true** for the field elasticsearch.index.name

3. Now, the indices tab of Stack Monitoring is working fine.

---

<div class="post-metadata">

**Author:** ![gbschenkel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbschenkel/32/96985_2.png) [@gbschenkel](https://discuss.elastic.co/u/gbschenkel)\
**Post date:** [August 12, 2026, 3:53pm UTC](https://discuss.elastic.co/t/indices-stack-monitoring-cannot-expand-inner-hits-for-collapse-field-index-stats-index/386205/4 "2026-08-12T15:53:42Z")

</div>

I was having this error, and didn't found the answer until now, tried to search here before, but I think was before your post/solution.

I think since AutoOps got free, people are using it instead of using Stack Monitoring.
