# Kibana dreaded timeout on dashboard

**URL:** <https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453>\
**Category:** Kibana\
**Created:** [March 21, 2017, 3:25pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453 "2017-03-21T15:25:56Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 21, 2017, 3:25pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/1 "2017-03-21T15:25:56Z")

</div>

Hello,

I would like to have help on this "$?$&!!\$#$%@%" problem 😃

I run ~70gb daily index size.. - 3 shards 1 replica on two server 64gb RAM, 31.94 heap size, 8 core CPU 3ghz  
YET if I try to go over 12hours of data on a dashboard ( 7visualization or less it is really annoying as hell and didnt notice really any "pattern".. ) I get a damn kibana timeout...

Any of you guyz could give me a hand on this ?

Ive run test... HEAP Usage is ok..

apparrentely its really the cpu that goes sky high ( load average 14 15, cpu usage stick a 100% for a bunch of time )  
Heap Usage is about 21gb out of 31.94gb ...

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 22, 2017, 2:56pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/2 "2017-03-22T14:56:20Z")

</div>

nobody, seriously ?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 22, 2017, 3:35pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/3 "2017-03-22T15:35:51Z")

</div>

I have a couple of questions about your situation:

1. What version of Kibana are you on?  
On later versions you have the search profiler which can help you detect which visualization is clogging your stuff.  
[https://www.elastic.co/blog/a-profile-a-day-keeps-the-doctor-away-the-elasticsearch-search-profiler](https://www.elastic.co/blog/a-profile-a-day-keeps-the-doctor-away-the-elasticsearch-search-profiler)  
You can check the statistics

2. You can also try to increase the timeout in the kibana.yml file:  
`elasticsearch.requestTimeout: 30000`

This is the default value in milliseconds, you can try to increase it.

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 22, 2017, 4:07pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/4 "2017-03-22T16:07:37Z")

</div>

already did the "requestTimeout" thing.

unfortunately it was a no go... its literaly as if it was not even taken in consideration...  
as for the version of kibana, im running 4.5.4

Thank you.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 22, 2017, 4:17pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/5 "2017-03-22T16:17:39Z")

</div>

If you query a volume that returns without a timeout and look at the response, e.g. through Chrome developer tools, is there any visualisation that takes much longer then the others?

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 22, 2017, 4:24pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/6 "2017-03-22T16:24:48Z")

</div>

sorry but... do you have a little bit more explanation ?

I can get 15minutes 7 visualization. at once. no problem at all. up to 12 hours in fact.. ( most of the time ) BUT cannot go past it ...

What do you want me to do exactly or "provide" ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 22, 2017, 4:32pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/7 "2017-03-22T16:32:06Z")

</div>

If you request a few hours worth of data, you should be able to view the statistics (which includes time the aggregation took to ran) for each visualisation [from within Kibana](https://www.elastic.co/guide/en/kibana/4.5/area-chart.html#area-viewing-detailed-information). If you look at the different visualisations and how long they took, is there any that stands out?

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 22, 2017, 4:39pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/8 "2017-03-22T16:39:10Z")

</div>

ill try to give it a shot.  
Using F12 developper mode ? any specific tabs i should provide you information from ?

btw, thank you

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 22, 2017, 4:48pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/9 "2017-03-22T16:48:54Z")

</div>

In each visualisation there is an upwards arrow in the lower left corner. If you click on this you should see a button that says 'Statistics', which will provide this information.

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 22, 2017, 4:54pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/10 "2017-03-22T16:54:54Z")

</div>

## 12 hours

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a7f972d8e19b77d3a7ad74ec41ea3f0b57e1b46d.png)  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7db1381b9fef27b6637773a683bf65fb6b997b96.png)  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1cf19d9ac9951c237bce332076cbc98d618e4d76.png)

and a last one that is simply a "search view" in my dashboard ( so no stats )

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 22, 2017, 5:11pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/11 "2017-03-22T17:11:23Z")

</div>

It looks like you have some visualisations that require a lot of computation, especially the bottom one. If you are maxing out all CPU cores on both machines while querying, you may have hit the limit for what your cluster can handle, and may need to either try to make your dashboards less computationally intensive or scale out.

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 22, 2017, 5:21pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/12 "2017-03-22T17:21:14Z")

</div>

IF scaling out is not an option .. what option left do I have ?  
btw. i just "removed" the botton visualisation, and tried to load the last 7days,

its a no go..

24hours, same thing.  
12hours same thing .. so right now. cpu is loaded the hell up !

cpu usage 23% one nodes load av. 14, 10% the other one load av. 8

once the load dropped. I could load a view of the last 24hours.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 22, 2017, 5:24pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/13 "2017-03-22T17:24:07Z")

</div>

How long is your retention period?

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 22, 2017, 5:25pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/14 "2017-03-22T17:25:11Z")

</div>

we plan, to be able to visualize up to three month of data. ( one month at once if needed.. but up to 3month active ) 1 year in archives

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 22, 2017, 5:41pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/15 "2017-03-22T17:41:35Z")

</div>

Upgrading to the latest 5.x release might actually help you. The 5.x releases have improved how caching works for indices covered entirely by the time period queried. If you used indices (with a single primary shard) that covered a smaller time period, e.g. a few hours, a good portion of the indices would be able to cache results for queries spanning longer time periods, resulting in faster response times. There is even a new [rollover API](https://www.elastic.co/guide/en/elasticsearch/reference/5.2/indices-rollover-index.html) that would allow you to create indices of a certain size irrespective of time period which may make this even easier to manage. The drawback with this approach is naturally that you may end up with a larger number of shards, which could become a problem for long term retention.

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 22, 2017, 5:44pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/16 "2017-03-22T17:44:53Z")

</div>

ok, so .. if I understand correctely . so long so far... im fuck\*d ?

so .. how would I calculate adequately what I would need in term of CPU power ? if ever i was to scale horizontaly ... ?  
please.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 22, 2017, 5:45pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/17 "2017-03-22T17:45:56Z")

</div>

Why is upgrading not an option?

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 22, 2017, 5:48pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/18 "2017-03-22T17:48:58Z")

</div>

im running Siemonster Stack. its sort of all in one bundle with ossec etc...  
so I assume its version dependant + you said that in the long term, I would have a problem with number of shards...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 22, 2017, 5:58pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/19 "2017-03-22T17:58:00Z")

</div>

If we assume 4 hours per index with 1 primary and 1 replica shard, you would get 360 shards per month. With that 3 months online retention should be fine with your current setup. You may even be able to stretch it quite a bit further, so I would not worry about that.

Apart from upgrading or making the visualisations more light-weight, I do not really have any good suggestions at the moment. Maybe someone else will chime in?

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [March 22, 2017, 6:11pm UTC](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453/20 "2017-03-22T18:11:32Z")

</div>

so my problem right now is how my "shards" are made ?

 ![](https://us1.discourse-cdn.com/elastic/original/3X/6/e/6e3fdc35b47b3e4d8fe3fe78bfe53f0ec1eb1854.png)

[Next page](https://discuss.elastic.co/t/kibana-dreaded-timeout-on-dashboard/79453.md?page=2)
