# Kibana requesting too many doc values

**URL:** <https://discuss.elastic.co/t/kibana-requesting-too-many-doc-values/147760>\
**Category:** Kibana\
**Created:** [September 7, 2018, 7:30pm UTC](https://discuss.elastic.co/t/kibana-requesting-too-many-doc-values/147760 "2018-09-07T19:30:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mightyguava](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mightyguava](https://discuss.elastic.co/u/mightyguava)\
**Post date:** [September 7, 2018, 7:30pm UTC](https://discuss.elastic.co/t/kibana-requesting-too-many-doc-values/147760/1 "2018-09-07T19:30:56Z")

</div>

We have an elasticsearch cluster that indexes some events that flow through our system for debugging use. These events have pretty widely varying formats, so they end up generating a lot of different fields. Kibana maps about 2000 fields for the indexes. We don't configure these indexes manually, and just let Elasticsearch automatically generate indexes based on the data.

Performance has never been a problem. Type conflicts are pretty rare and haven't been problematic enough to warrant any action.

Today, I refreshed field mappings, and all search queries are breaking with the following error. It looks like the indexes now have 101 different date type fields. Kibana seems to automatically request every date fields as docvalue fields in every single request.

These are for "Discover" requests, and we don't ever sort/aggregate on any of these fields. Is there a way to keep Kibana from requesting these fields as docvalue fields?

If not, how can we get Kibana working again? Update max\_docvalue\_fields\_search for every index?

`{"responses":[{"took":2480,"timed_out":false,"_shards":{"total":5695,"successful":5600,"skipped":5600,"failed":95,"failures":[{"shard":0,"index":"tracer--2018-09-07","node":"rMepPe8BS1m2ILlUDDQFmg","reason":{"type":"illegal_argument_exception","reason":"Trying to retrieve too many docvalue_fields. Must be less than or equal to: [100] but was [101]. This limit can be set by changing the [index.max_docvalue_fields_search] index level setting."}}]},"hits":{"total":0,"max_score":0.0,"hits":[]},"status":200}]}`

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [September 10, 2018, 4:14pm UTC](https://discuss.elastic.co/t/kibana-requesting-too-many-doc-values/147760/2 "2018-09-10T16:14:23Z")

</div>

Hi Yunchi, this is a tough one. I spoke to some other engineers on the team, and we think you have a few options to try:

1. As you suggested, you could try increasing `max_docvalue_fields_search` for each index, though I have concerns this might not scale. If you continue to index documents with new fields then you'll probably bump up against this limit again.
2. If you don't actually need to query/aggregate on all of those date fields, then maybe you could try mapping them as strings instead. Then they won't be requested as docvalue fields.
3. You could also be trying to fit too many different types of data into a single index pattern, i.e. your index pattern is too greedy. Would your use case could allow you to define index patterns which match fewer indices, and thus include fewer date fields?

I hope this helps,  
CJ

---

<div class="post-metadata">

**Author:** ![mightyguava](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mightyguava](https://discuss.elastic.co/u/mightyguava)\
**Post date:** [September 10, 2018, 7:10pm UTC](https://discuss.elastic.co/t/kibana-requesting-too-many-doc-values/147760/3 "2018-09-10T19:10:50Z")

</div>

Hi CJ, thanks for asking the team. I ended up bumping `max_docvalue_fields_search` for now and that has worked out.

I think mapping them to strings is the next best option, and that's what I'll probably do when the next time this comes up. I really wanted to avoid having to create mappings manually though, since the schema is pretty arbitrary.

As for using a single index pattern, I do usually want my query to hit all indexes in Kibana. The events are usually for the same domain object, but within different stages of its life cycle, so querying by some common fields is good for reconstructing a sequence of events across systems. I believe that with a single query, I can only query one index pattern?

Why is there no way to limit which fields get queried as doc values in Kibana?

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [September 10, 2018, 7:34pm UTC](https://discuss.elastic.co/t/kibana-requesting-too-many-doc-values/147760/4 "2018-09-10T19:34:29Z")

</div>

> I believe that with a single query, I can only query one index pattern?

This is correct, but you can use commas in your index pattern to define one which matches different index naming schemes, e.g. `foo*,bar*` will match indices matching `foo*` as well as `bar*`.

> Why is there no way to limit which fields get queried as doc values in Kibana?

I don't know the answer to this one, but it sounds like a good feature request. If you'd like to see this supported, could you please file an [issue in GitHub](https://github.com/elastic/kibana/issues/new?template=Feature_request.md) with a summary of the functionality you'd like to see, a recap of why you need this, and a cross-link to this thread for reference?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2018, 7:34pm UTC](https://discuss.elastic.co/t/kibana-requesting-too-many-doc-values/147760/5 "2018-10-08T19:34:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [December 3, 2020, 3:40pm UTC](https://discuss.elastic.co/t/kibana-requesting-too-many-doc-values/147760/6 "2020-12-03T15:40:07Z")

</div>

Just a note for anyone who might stumble across this old thread: The docvalues limit should no longer be causing problems starting in 7.11, as we shifted over to using the [search fields API](https://www.elastic.co/guide/en/elasticsearch/reference/master/search-fields.html#search-fields) in this PR: [https://github.com/elastic/kibana/pull/82383](https://github.com/elastic/kibana/pull/82383)
