# Kibana dashbboard times out with large ES data

**URL:** <https://discuss.elastic.co/t/kibana-dashbboard-times-out-with-large-es-data/108369>\
**Category:** Kibana\
**Created:** [November 20, 2017, 11:10am UTC](https://discuss.elastic.co/t/kibana-dashbboard-times-out-with-large-es-data/108369 "2017-11-20T11:10:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![antoine.brun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antoine.brun/32/95307_2.png) [@antoine.brun](https://discuss.elastic.co/u/antoine.brun)\
**Post date:** [November 20, 2017, 11:10am UTC](https://discuss.elastic.co/t/kibana-dashbboard-times-out-with-large-es-data/108369/1 "2017-11-20T11:10:11Z")

</div>

Hello,

we have a production ES cluster (v2.4) with 4 data nodes (24Gb, 4CPU) (a screenshot below shows the full cluster details.

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/7/27c39429e22b53bc55b00c84f86ecffc1256dc96.png)

There are 2,668,920,207 docs in the cluster, these are syslogs collected from a UTM device.  
These docs are distributed over 356 index (one per day), index name format is **ubilogs-**

We are using Kibana to show dashboard and we use **ubilogs-** \* to build our visualisations and dashboards and most of the time Kibana times out when trying to build the visualisations even if the time range is very short (15 min, 1h,...)  
It seems that the search from Kibana is searchig over all indexes even for a small time range.

Is there a way to control this or optimise?  
If we want a dashboard over last 1h, it should only search in a few index (only one actually) and it shouldn't time out

Antoine

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [November 20, 2017, 6:01pm UTC](https://discuss.elastic.co/t/kibana-dashbboard-times-out-with-large-es-data/108369/2 "2017-11-20T18:01:18Z")

</div>

This is supported in 4.6, the configuration for it would happen on the index pattern creation page. Specifying a time field should be sufficient, or you can use the deprecated event time based index names. Can you confirm that the index pattern in kibana is configured with a time field?

---

<div class="post-metadata">

**Author:** ![Mayotte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayotte/32/24914_2.png) [@Mayotte](https://discuss.elastic.co/u/Mayotte)\
**Post date:** [November 24, 2017, 10:44am UTC](https://discuss.elastic.co/t/kibana-dashbboard-times-out-with-large-es-data/108369/3 "2017-11-24T10:44:43Z")

</div>

Hi Jon,

We can confirm that we use time field.

Thanks,  
Diyaldine

---

<div class="post-metadata">

**Author:** ![Mayotte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayotte/32/24914_2.png) [@Mayotte](https://discuss.elastic.co/u/Mayotte)\
**Post date:** [November 27, 2017, 2:02pm UTC](https://discuss.elastic.co/t/kibana-dashbboard-times-out-with-large-es-data/108369/4 "2017-11-27T14:02:07Z")

</div>

Hello,

We have already updated to Kibana 4.6.6

We remarked that when in a dashboard, we have visualizations with aggregation with 8 fields for example (as below) it's take more time to display or a timeout error is sent.

 ![perf](https://us1.discourse-cdn.com/elastic/original/3X/9/8/986894b98806a88e344b544b77bd7ac36e186a20.PNG)

So, are there few configurations that we must to apply in Kibana or Elasticsearch side concerning fields used in visualizations with aggregations ?

Thanks,  
Diyaldine

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2017, 2:02pm UTC](https://discuss.elastic.co/t/kibana-dashbboard-times-out-with-large-es-data/108369/5 "2017-12-25T14:02:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
