# Kibana all of a sudden requesting a larger result\_window?

**URL:** <https://discuss.elastic.co/t/kibana-all-of-a-sudden-requesting-a-larger-result-window/322945>\
**Category:** Kibana\
**Created:** [January 11, 2023, 3:17pm UTC](https://discuss.elastic.co/t/kibana-all-of-a-sudden-requesting-a-larger-result-window/322945 "2023-01-11T15:17:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gborg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gborg/32/58934_2.png) [@gborg](https://discuss.elastic.co/u/gborg)\
**Post date:** [January 11, 2023, 3:17pm UTC](https://discuss.elastic.co/t/kibana-all-of-a-sudden-requesting-a-larger-result-window/322945/1 "2023-01-11T15:17:16Z")

</div>

Hello

I have a cluster with multiple elasticsearch nodes and a kibana server

I have not made any modifications to kibana recently, nor the indexing settings but all of a sudden one day I get "X of Y shards failed" and when I look into it the reason is that the "max\_result\_window" is 10'000, not 50'000

Why is kibana all of a sudden requesting 5 times as large result window ?

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [January 17, 2023, 12:21pm UTC](https://discuss.elastic.co/t/kibana-all-of-a-sudden-requesting-a-larger-result-window/322945/2 "2023-01-17T12:21:04Z")

</div>

As far as I know, Kibana does not change that setting directly and it will honor the actual value set up on the index (the default is 10k, yes)

For example, on this discussion the Maps application is needing read access to that setting.

> <https://github.com/elastic/kibana/issues/53523>
>
> The Maps application uses index settings \`max\_result\_window\` and \`max\_inner\_resu…lt\_window\` in \`\_search\` requests to know the maximum number of documents to request and maximum number of top hits to request.
> 
> Currently, the only way to fetch index settings is to use \`callWithRequest\` which uses the user's permissions. The problem is that users may have read access to the index yet not have \`view\_index\_metadata\` to allow read access to index settings. This puts our usability in a difficult situation. In the case that the user does not have \`view\_index\_metadata\` then we have to display crufty messaging about missing permissions and fall back to default values. These default values could cause \`\_search\` request errors. For example, if \`max\_result\_window\` is set to a smaller value then the default, \`\_search\` requests with the default \`max\_result\_window\`will fail with another super crufty message.
> 
> For these cases, we would like to use Kibana's user to access the data index settings so we always have the right values regardless of user permissions.

Anyways, that setting is associated with each index and can be changed anytime as documented [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules.html#dynamic-index-settings). Maybe you need to take a look at your indices in case this setting has changed on any of them?

---

<div class="post-metadata">

**Author:** ![gborg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gborg/32/58934_2.png) [@gborg](https://discuss.elastic.co/u/gborg)\
**Post date:** [February 7, 2023, 3:41pm UTC](https://discuss.elastic.co/t/kibana-all-of-a-sudden-requesting-a-larger-result-window/322945/3 "2023-02-07T15:41:37Z")

</div>

If anyone enters this thread with the same issue as me .....

In my case it seems that sometime in the past I have edited the "advanced kibana setting" of "Discover:sampleSize" and restoring that to a lower value fixed this

Same as here

> [@Discover: Result window is too large, from + size must be less than or equal to: \[10000\]](https://discuss.elastic.co/t/discover-result-window-is-too-large-from-size-must-be-less-than-or-equal-to-10000/257112):
>
> Hi All, In an ES 6.8.6 cluster, I created an index pattern in Kibana and when I went to discover tab, I got the error Discover: Result window is too large, from + size must be less than or equal to: [10000] but was [200000]. See the scroll api for a more efficient way to request large data sets. This limit can be set by changing the [index.max\_result\_window] index level setting The indices are huge containing millions of docs. But how am I supposed t…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2023, 3:42pm UTC](https://discuss.elastic.co/t/kibana-all-of-a-sudden-requesting-a-larger-result-window/322945/4 "2023-03-07T15:42:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
