# Kibana index is unresponsive

**URL:** <https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575>\
**Category:** Kibana\
**Created:** [June 19, 2018, 10:12pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575 "2018-06-19T22:12:34Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Piyush\_Pattanayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush_pattanayak/32/32461_2.png) [@Piyush\_Pattanayak](https://discuss.elastic.co/u/Piyush_Pattanayak)\
**Post date:** [June 19, 2018, 10:12pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/1 "2018-06-19T22:12:34Z")

</div>

I created an index in Kibana using wildcard which is unresponsive, which means I cannot select it, it won't show any fields in the management tab, it just keeps loading in the discover tab. However, it works fine when I create the index using the exact name of the index. Is there a limit on the number of records an index can load because the index I am trying to create has more than 400 million records.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [June 20, 2018, 3:59pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/2 "2018-06-20T15:59:01Z")

</div>

Hi,

How many indices the index pattern encapsulates, and how many unique fields are within those.

Can you try this: `http://localhost:9200/_field_caps?index=logstash-*&fields=*&ignore_unavailable&allow_no_indices`  
Replacing `logstash-*` with your index pattern.

I think yours is a very expensive operation from what I understand.

Am also tagging @Bill_McConaghy for more insights into this .

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![Piyush\_Pattanayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush_pattanayak/32/32461_2.png) [@Piyush\_Pattanayak](https://discuss.elastic.co/u/Piyush_Pattanayak)\
**Post date:** [June 20, 2018, 5:05pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/3 "2018-06-20T17:05:14Z")

</div>

I ran the query you mentioned and I got the response.

```
{
"error": {
"root_cause": [
{
"type": "illegal_argument_exception",
"reason": "No endpoint or operation is available at [_field_caps]"
}
],
"type": "illegal_argument_exception",
"reason": "No endpoint or operation is available at [_field_caps]"
},
"status": 400
}

```

I tried the link with more than one index. Everything has the same response.

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [June 20, 2018, 5:37pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/4 "2018-06-20T17:37:01Z")

</div>

When you use the wildcard, does it match multiple indices? The gathering of field metadata can be expensive, especially if one of the indices lives on a slow node.

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [June 20, 2018, 5:37pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/5 "2018-06-20T17:37:35Z")

</div>

Also, what version of the Elastic stack are you running?

---

<div class="post-metadata">

**Author:** ![Piyush\_Pattanayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush_pattanayak/32/32461_2.png) [@Piyush\_Pattanayak](https://discuss.elastic.co/u/Piyush_Pattanayak)\
**Post date:** [June 20, 2018, 6:38pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/6 "2018-06-20T18:38:19Z")

</div>

Correct me if I am wrong, by multiple indices do you mean if logstash-\* also includes another index logstash-new-\*. If this is the case then no it does not include multiple indices.

Elastic Search Version: 5.2.2

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [June 20, 2018, 6:43pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/7 "2018-06-20T18:43:25Z")

</div>

Yup that was my question. So there is only 1 index that matches logstash-\*. Not sure why the two would behave differently. @chrisronline any ideas?

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [June 20, 2018, 7:01pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/8 "2018-06-20T19:01:51Z")

</div>

We changed how we retrieve data about indices on the management tag in 5.5.x. This change might help your use case. Are you able to upgrade and test it out?

---

<div class="post-metadata">

**Author:** ![Piyush\_Pattanayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush_pattanayak/32/32461_2.png) [@Piyush\_Pattanayak](https://discuss.elastic.co/u/Piyush_Pattanayak)\
**Post date:** [June 20, 2018, 8:04pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/9 "2018-06-20T20:04:18Z")

</div>

I am using an enterprise version of elastic search. I am not sure if it can be upgraded.

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [June 20, 2018, 8:17pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/10 "2018-06-20T20:17:31Z")

</div>

What is the response if you issue this query in the Dev Tools:

```auto
GET _field_caps?index=<insert_name_of_index>&fields=*

```

Remember to change `<insert_name_of_index>` to the actual name of your index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2018, 8:17pm UTC](https://discuss.elastic.co/t/kibana-index-is-unresponsive/136575/11 "2018-07-18T20:17:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
