# Kibana Monitoring Dashboard showing wrong info

**URL:** https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605
**Category:** Kibana
**Created:** [October 29, 2019, 7:23am UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605 "2019-10-29T07:23:33Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![akshaymaniyar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akshaymaniyar/32/45836_2.png) [@akshaymaniyar](https://discuss.elastic.co/u/akshaymaniyar)
#### Post date: [October 29, 2019, 7:23am UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605/1 "2019-10-29T07:23:34Z")

</div>

The status of every index is being wrongly shown as Deleted / Closed. But all the indices are very much in Green state.

 ![24%20PM](https://us1.discourse-cdn.com/elastic/original/3X/1/9/19146dd8fab1af43709a2c5293cbee71ae5be864.png)

---

<div class="post-metadata">

### Author: ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)
#### Post date: [October 29, 2019, 10:40am UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605/2 "2019-10-29T10:40:04Z")

</div>

Hi @akshaymaniyar  
the status of your cluster is green if everything is correctly allocated. The state of each index doesn't directly influence the state of your cluster. If the closed index was in a yellow state your cluster will be in a yellow state.  
In your case seems that your cluster state is good and the table reports that some of your indexes were deleted or closed.

---

<div class="post-metadata">

### Author: ![akshaymaniyar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akshaymaniyar/32/45836_2.png) [@akshaymaniyar](https://discuss.elastic.co/u/akshaymaniyar)
#### Post date: [October 29, 2019, 2:14pm UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605/3 "2019-10-29T14:14:56Z")

</div>

It is showing this for all indices, whereas none of them are in either deleted or closed state.

---

<div class="post-metadata">

### Author: ![Mike\_Place](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_place/32/39555_2.png) [@Mike\_Place](https://discuss.elastic.co/u/Mike_Place)
#### Post date: [October 30, 2019, 1:47pm UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605/4 "2019-10-30T13:47:16Z")

</div>

Hi @akshaymaniyar

Could we please see the results of a couple queries?

On your production cluster:

`GET /_cat/indices`

On your monitoring cluster:

```auto
POST .monitoring-es*/_search?filter_path=aggregations.by_cluster_uuid.buckets.key,aggregations.by_cluster_uuid.buckets.by_doc_type.buckets.key,aggregations.by_cluster_uuid.buckets.by_doc_type.buckets.latest_timestamp.value_as_string
{
  "size": 0,
  "aggs": {
    "by_cluster_uuid": {
      "terms": {
        "field": "cluster_uuid",
        "size": 10
      },
      "aggs": {
        "by_doc_type": {
          "terms": {
            "field": "type",
            "size": 10
          },
          "aggs": {
            "latest_timestamp": {
              "max": {
                "field": "timestamp"
              }
            }
          }
        }
      }
    }
  }
}

```

Thanks!

---

<div class="post-metadata">

### Author: ![akshaymaniyar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akshaymaniyar/32/45836_2.png) [@akshaymaniyar](https://discuss.elastic.co/u/akshaymaniyar)
#### Post date: [October 31, 2019, 6:05am UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605/5 "2019-10-31T06:05:37Z")

</div>

/\_cat/indices =\> Output

> <https://gist.github.com/akshaymaniyar/e3b9682daebcc5e1d51a1ff83e00b7a4>

Query Output

> <https://gist.github.com/akshaymaniyar/ffd395f121c91099cdbf06d30270969d>

---

<div class="post-metadata">

### Author: ![akshaymaniyar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akshaymaniyar/32/45836_2.png) [@akshaymaniyar](https://discuss.elastic.co/u/akshaymaniyar)
#### Post date: [November 3, 2019, 1:35pm UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605/6 "2019-11-03T13:35:46Z")

</div>

@Mike_Place: Plz suggest what is to be done to correct the issue?

---

<div class="post-metadata">

### Author: ![akshaymaniyar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akshaymaniyar/32/45836_2.png) [@akshaymaniyar](https://discuss.elastic.co/u/akshaymaniyar)
#### Post date: [November 5, 2019, 6:41am UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605/7 "2019-11-05T06:41:37Z")

</div>

bump

---

<div class="post-metadata">

### Author: ![Mike\_Place](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_place/32/39555_2.png) [@Mike\_Place](https://discuss.elastic.co/u/Mike_Place)
#### Post date: [November 13, 2019, 11:43am UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605/8 "2019-11-13T11:43:02Z")

</div>

@akshaymaniyar You have some many indices defined here that I wonder if perhaps you are hitting the max\_bucket\_size when we try to aggregate the results for the query for your index data. When you load this page, do you observe any errors in either the browser, the Kibana server log, or the Elasticsearch log where monitoring data is stored?

---

<div class="post-metadata">

### Author: ![akshaymaniyar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akshaymaniyar/32/45836_2.png) [@akshaymaniyar](https://discuss.elastic.co/u/akshaymaniyar)
#### Post date: [November 16, 2019, 2:26pm UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605/9 "2019-11-16T14:26:43Z")

</div>

Yes that was indeed the issue. It is resolved by increasing the "search.max\_buckets".

We were getting the below error:

```
Caused by: org.elasticsearch.search.aggregations.MultiBucketConsumerService$TooManyBucketsException: Trying to create too many buckets. Must be less than or equal to: [20000] but was [20001]. This limit can be set by changing the [search.max_buckets] cluster level setting.
	at org.elasticsearch.search.aggregations.MultiBucketConsumerService$MultiBucketConsumer.accept(MultiBucketConsumerService.java:110) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.bucket.BucketsAggregator.consumeBucketsAndMaybeBreak(BucketsAggregator.java:132) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.bucket.terms.LongTermsAggregator.buildAggregation(LongTermsAggregator.java:148) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.AggregatorFactory$MultiBucketAggregatorWrapper.buildAggregation(AggregatorFactory.java:152) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.bucket.BestBucketsDeferringCollector$2.buildAggregation(BestBucketsDeferringCollector.java:214) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.bucket.BucketsAggregator.bucketAggregations(BucketsAggregator.java:141) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.bucket.terms.GlobalOrdinalsStringTermsAggregator.buildAggregation(GlobalOrdinalsStringTermsAggregator.java:238) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.AggregatorFactory$MultiBucketAggregatorWrapper.buildAggregation(AggregatorFactory.java:152) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.bucket.BestBucketsDeferringCollector$2.buildAggregation(BestBucketsDeferringCollector.java:214) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.bucket.BucketsAggregator.bucketAggregations(BucketsAggregator.java:141) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.bucket.terms.GlobalOrdinalsStringTermsAggregator.buildAggregation(GlobalOrdinalsStringTermsAggregator.java:238) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.aggregations.AggregationPhase.execute(AggregationPhase.java:130) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.query.QueryPhase.execute(QueryPhase.java:121) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.indices.IndicesService.lambda$loadIntoContext$18(IndicesService.java:1272) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.indices.IndicesService.lambda$cacheShardLevelResult$19(IndicesService.java:1329) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.indices.IndicesRequestCache$Loader.load(IndicesRequestCache.java:174) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.indices.IndicesRequestCache$Loader.load(IndicesRequestCache.java:157) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.common.cache.Cache.computeIfAbsent(Cache.java:433) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.indices.IndicesRequestCache.getOrCompute(IndicesRequestCache.java:123) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.indices.IndicesService.cacheShardLevelResult(IndicesService.java:1335) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.indices.IndicesService.loadIntoContext(IndicesService.java:1269) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.SearchService.loadOrExecuteQueryPhase(SearchService.java:347) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:393) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.SearchService.access$100(SearchService.java:124) ~[elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.SearchService$2.onResponse(SearchService.java:358) [elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.SearchService$2.onResponse(SearchService.java:354) [elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.search.SearchService$4.doRun(SearchService.java:1069) [elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.common.util.concurrent.TimedRunnable.doRun(TimedRunnable.java:41) [elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingAbstractRunnable.doRun(ThreadContext.java:751) [elasticsearch-7.0.1.jar:7.0.1]
	at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-7.0.1.jar:7.0.1]
	at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) [?:?]
	at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) [?:?]
	at java.lang.Thread.run(Thread.java:835) [?:?]
```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 14, 2019, 2:26pm UTC](https://discuss.elastic.co/t/kibana-monitoring-dashboard-showing-wrong-info/205605/10 "2019-12-14T14:26:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
