# Kibana shows Shard Failures

**URL:** <https://discuss.elastic.co/t/kibana-shows-shard-failures/37779>\
**Category:** Elasticsearch\
**Created:** [December 22, 2015, 6:17pm UTC](https://discuss.elastic.co/t/kibana-shows-shard-failures/37779 "2015-12-22T18:17:17Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ananthanaidu](https://avatars.discourse-cdn.com/v4/letter/a/f08c70/32.png) [@ananthanaidu](https://discuss.elastic.co/u/ananthanaidu)\
**Post date:** [December 22, 2015, 6:17pm UTC](https://discuss.elastic.co/t/kibana-shows-shard-failures/37779/1 "2015-12-22T18:17:17Z")

</div>

HI Greetings,

Can you please help to fix below kibana error,

**Shard Failures**

Index: weblogs-2015.12.07 Shard: 0 Reason: ElasticsearchException[org.elasticsearch.common.breaker.CircuitBreakingException: [FIELDDATA] Data too large, data for [@timestamp] would be larger than limit of [6431991398/5.9gb]]; nested: UncheckedExecutionException[org.elasticsearch.common.breaker.CircuitBreakingException: [FIELDDATA] Data too large, data for [@timestamp] would be larger than limit of [6431991398/5.9gb]]; nested: CircuitBreakingException[[FIELDDATA] Data too large, data for [@timestamp] would be larger than limit of [6431991398/5.9gb]];

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [December 22, 2015, 6:39pm UTC](https://discuss.elastic.co/t/kibana-shows-shard-failures/37779/2 "2015-12-22T18:39:13Z")

</div>

I _think_ this is an elasticsearch issue, not a kibana issue. Kibana is just showing you the error that came from elasticsearch. I'm not sure how to move this to the elasticsearch discuss topic or if you would start another discussion there.

---

<div class="post-metadata">

**Author:** ![ananthanaidu](https://avatars.discourse-cdn.com/v4/letter/a/f08c70/32.png) [@ananthanaidu](https://discuss.elastic.co/u/ananthanaidu)\
**Post date:** [December 22, 2015, 6:43pm UTC](https://discuss.elastic.co/t/kibana-shows-shard-failures/37779/3 "2015-12-22T18:43:23Z")

</div>

Yes, I have moved to Elastic search.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 22, 2015, 8:11pm UTC](https://discuss.elastic.co/t/kibana-shows-shard-failures/37779/4 "2015-12-22T20:11:18Z")

</div>

Yep it's an ES issue, it means your query would have caused an OOM and so it was stopped.

In this case you need to either add more heap to your/add more nodes, reduce the timeframe of the query or reindex everything set as `not_analyzed` to doc values.

---

<div class="post-metadata">

**Author:** ![sreejith](https://avatars.discourse-cdn.com/v4/letter/s/e9bcb4/32.png) [@sreejith](https://discuss.elastic.co/u/sreejith)\
**Post date:** [May 19, 2016, 8:01pm UTC](https://discuss.elastic.co/t/kibana-shows-shard-failures/37779/5 "2016-05-19T20:01:13Z")

</div>

could you please let me know how to configure this "everything set as not\_analyzed to doc values".

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 23, 2016, 3:49am UTC](https://discuss.elastic.co/t/kibana-shows-shard-failures/37779/6 "2016-05-23T03:49:22Z")

</div>

Have a look at [https://www.elastic.co/guide/en/elasticsearch/reference/2.3/doc-values.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.3/doc-values.html)

---

<div class="post-metadata">

**Author:** ![rsjavier](https://avatars.discourse-cdn.com/v4/letter/r/9e8a1a/32.png) [@rsjavier](https://discuss.elastic.co/u/rsjavier)\
**Post date:** [June 6, 2016, 8:21am UTC](https://discuss.elastic.co/t/kibana-shows-shard-failures/37779/7 "2016-06-06T08:21:24Z")

</div>

I used the multi\_field type so that i can have the raw data which is not\_analyzed and another one that is analyzed and can be search.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:46pm UTC](https://discuss.elastic.co/t/kibana-shows-shard-failures/37779/8 "2017-07-05T22:46:01Z")

</div>


