# Kibana timeout but curl with same query works perfectly

**URL:** <https://discuss.elastic.co/t/kibana-timeout-but-curl-with-same-query-works-perfectly/258405>\
**Category:** Kibana\
**Created:** [December 11, 2020, 11:30am UTC](https://discuss.elastic.co/t/kibana-timeout-but-curl-with-same-query-works-perfectly/258405 "2020-12-11T11:30:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Julio\_reyes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julio_reyes/32/45243_2.png) [@Julio\_reyes](https://discuss.elastic.co/u/Julio_reyes)\
**Post date:** [December 11, 2020, 11:30am UTC](https://discuss.elastic.co/t/kibana-timeout-but-curl-with-same-query-works-perfectly/258405/1 "2020-12-11T11:30:41Z")

</div>

Hi, I'm facing an issue from kibana. Trying to fetch the data of last 90 days I get a timeout. After that I tried to make a curl to the server using the full request that kibana runs in the inspect windows and curl worked perfectly fetching all the data.

Watching kibana logs I didn't see any error but maybe it tells you something.

```
{"type":"response","@timestamp":"2020-12-11T09:50:21Z","tags":[],"pid":1,"method":"post","statusCode":200,"req":{"url":"/api/ui_metric/report","method":"post","headers":{"connection":"upgrade","host":"url/kibana","x-real-ip":"1.1.1.1","x-forwarded-for":"1.1.1.1","x-forwarded-proto":"https","x-forwarded-host":"url/kibana","x-forwarded-port":"443","content-length":"122","user-agent":"Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0","accept":"*/*","accept-language":"es-ES,es;q=0.8,en-US;q=0.5,en;q=0.3","accept-encoding":"gzip, deflate, br","referer":"url/kibana","content-type":"application/json","kbn-version":"7.7.0","origin":"https://url/kibana"},"remoteAddress":"1.1.1.1","userAgent":"1.1.1.1","referer":"https://url/kibana"},"res":{"statusCode":200,"responseTime":987,"contentLength":9},"message":"POST /api/ui_metric/report 200 987ms - 9.0B"}
{"type":"response","@timestamp":"2020-12-11T09:50:29Z","tags":[],"pid":1,"method":"get","statusCode":200,"req":{"url":"/login","method":"get","headers":{"host":"1.1.1.1:5601","user-agent":"kube-probe/1.14+","accept-encoding":"gzip","connection":"close"},"remoteAddress":"1.1.1.1","userAgent":"1.1.1.1"},"res":{"statusCode":200,"responseTime":8,"contentLength":9},"message":"GET /login 200 8ms - 9.0B"}
{"type":"response","@timestamp":"2020-12-11T09:50:49Z","tags":[],"pid":1,"method":"get","statusCode":200,"req":{"url":"/login","method":"get","headers":{"host":"1.1.1.1:5601","user-agent":"kube-probe/1.14+","accept-encoding":"gzip","connection":"close"},"remoteAddress":"1.1.1.1","userAgent":"1.1.1.1"},"res":{"statusCode":200,"responseTime":9,"contentLength":9},"message":"GET /login 200 9ms - 9.0B"}
{"type":"response","@timestamp":"2020-12-11T09:51:09Z","tags":[],"pid":1,"method":"get","statusCode":200,"req":{"url":"/login","method":"get","headers":{"host":"1.1.1.1:5601","user-agent":"kube-probe/1.14+","accept-encoding":"gzip","connection":"close"},"remoteAddress":"1.1.1.1","userAgent":"1.1.1.1"},"res":{"statusCode":200,"responseTime":8,"contentLength":9},"message":"GET /login 200 8ms - 9.0B"}
{"type":"response","@timestamp":"2020-12-11T09:49:28Z","tags":[],"pid":1,"method":"post","statusCode":200,"req":{"url":"/internal/search/es","method":"post","headers":{"connection":"upgrade","host":"url","x-real-ip":"1.1.1.1","x-forwarded-for":"1.1.1.1","x-forwarded-proto":"https","x-forwarded-host":"url","x-forwarded-port":"443","content-length":"1883","user-agent":"Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0","accept":"*/*","accept-language":"es-ES,es;q=0.8,en-US;q=0.5,en;q=0.3","accept-encoding":"gzip, deflate, br","referer":"url/kibana","content-type":"application/json","kbn-version":"7.7.0","origin":"https://url/kibana"},"remoteAddress":"1.1.1.1","userAgent":"1.1.1.1","referer":"url/kibana"},"res":{"statusCode":200,"responseTime":120001,"contentLength":9},"message":"POST /internal/search/es 200 120001ms - 9.0B"}
{"type":"response","@timestamp":"2020-12-11T09:51:29Z","tags":[],"pid":1,"method":"get","statusCode":200,"req":{"url":"/login","method":"get","headers":{"host":"1.1.1.1:5601","user-agent":"kube-probe/1.14+","accept-encoding":"gzip","connection":"close"},"remoteAddress":"1.1.1.1","userAgent":"1.1.1.1"},"res":{"statusCode":200,"responseTime":9,"contentLength":9},"message":"GET /login 200 9ms - 9.0B"}

```

The query I'm kibana is trying to request is:

```
{
  "version": true,
  "size": "100",
  "sort": [
    {
      "timestamp": {
        "order": "desc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "aggs": {
    "2": {
      "date_histogram": {
        "field": "timestamp",
        "calendar_interval": "1d",
        "time_zone": "Europe/Madrid",
        "min_doc_count": 1
      }
    }
  },
  "stored_fields": [
    "*"
  ],
  "script_fields": {},
  "docvalue_fields": [
    {
      "field": "timestamp",
      "format": "date_time"
    },
    {
      "field": "data.aws.created-at",
      "format": "date_time"
    },
    {
      "field": "data.aws.createdAt",
      "format": "date_time"
    },
    {
      "field": "data.aws.end",
      "format": "date_time"
    },
    {
      "field": "data.aws.resource.instanceDetails.launchTime",
      "format": "date_time"
    },
    {
      "field": "data.aws.service.eventFirstSeen",
      "format": "date_time"
    },
    {
      "field": "data.aws.service.eventLastSeen",
      "format": "date_time"
    },
    {
      "field": "data.aws.start",
      "format": "date_time"
    },
    {
      "field": "data.aws.summary.Time Range.end",
      "format": "date_time"
    },
    {
      "field": "data.aws.summary.Time Range.start",
      "format": "date_time"
    },
    {
      "field": "data.aws.updatedAt",
      "format": "date_time"
    },
    {
      "field": "data.columns.datetime",
      "format": "date_time"
    },
    {
      "field": "data.columns.iso_8601",
      "format": "date_time"
    },
    {
      "field": "data.vulnerability.published",
      "format": "date_time"
    },
    {
      "field": "syscheck.mtime_after",
      "format": "date_time"
    },
    {
      "field": "syscheck.mtime_before",
      "format": "date_time"
    },
    {
      "field": "data.cis.timestamp",
      "format": "date_time"
    },
    {
      "field": "data.timestamp",
      "format": "date_time"
    }
  ],
  "_source": {
    "excludes": [
      "@timestamp"
    ]
  },
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "match_all": {}
        },
        {
          "range": {
            "timestamp": {
              "gte": "2020-09-12T10:42:03.361Z",
              "lte": "2020-12-11T11:42:03.361Z",
              "format": "strict_date_optional_time"
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  },
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {}
    },
    "fragment_size": 2147483647
  }
}

```

And curl run from Kibana's server is the following:

`curl -k -u elastic -X POST "https://opendistro-server:9200/indice*/_search" -H 'Content-Type: application/json' -d '{"track_total_hits": true,"version":true,"size":"100","sort":[{"timestamp":{"order":"desc","unmapped_type":"boolean"}}],"aggs":{"2":{"date_histogram":{"field":"timestamp","calendar_interval":"1d","time_zone":"Europe/Madrid","min_doc_count":1}}},"stored_fields":["*"],"script_fields":{},"docvalue_fields":[{"field":"timestamp","format":"date_time"},{"field":"data.aws.created-at","format":"date_time"},{"field":"data.aws.createdAt","format":"date_time"},{"field":"data.aws.end","format":"date_time"},{"field":"data.aws.resource.instanceDetails.launchTime","format":"date_time"},{"field":"data.aws.service.eventFirstSeen","format":"date_time"},{"field":"data.aws.service.eventLastSeen","format":"date_time"},{"field":"data.aws.start","format":"date_time"},{"field":"data.aws.summary.TimeRange.end","format":"date_time"},{"field":"data.aws.summary.TimeRange.start","format":"date_time"},{"field":"data.aws.updatedAt","format":"date_time"},{"field":"data.columns.datetime","format":"date_time"},{"field":"data.columns.iso_8601","format":"date_time"},{"field":"data.vulnerability.published","format":"date_time"},{"field":"syscheck.mtime_after","format":"date_time"},{"field":"syscheck.mtime_before","format":"date_time"},{"field":"data.cis.timestamp","format":"date_time"},{"field":"data.timestamp","format":"date_time"}],"_source":{"excludes":["@timestamp"]},"query":{"bool":{"must":[],"filter":[{"match_all":{}},{"range":{"timestamp":{"gte":"2020-09-12T07:36:04.661Z","lte":"2020-12-11T08:36:04.661Z","format":"strict_date_optional_time"}}}],"should":[],"must_not":[]}},"highlight":{"pre_tags":["@kibana-highlighted-field@"],"post_tags":["@/kibana-highlighted-field@"],"fields":{"*":{}},"fragment_size":2147483647}}'`

The number of hits is about 500000000 so is a big amount of data but I'm not sure if it related since Kibana is asking for 100, and the number of total hits.  
Any ideas about what can be happening??

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 11, 2020, 11:56am UTC](https://discuss.elastic.co/t/kibana-timeout-but-curl-with-same-query-works-perfectly/258405/2 "2020-12-11T11:56:32Z")

</div>

I had same isssue from long time. never reported as I thought it might be some parameter in kibana which is stopping this to finish.

---

<div class="post-metadata">

**Author:** ![Julio\_reyes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julio_reyes/32/45243_2.png) [@Julio\_reyes](https://discuss.elastic.co/u/Julio_reyes)\
**Post date:** [December 11, 2020, 1:28pm UTC](https://discuss.elastic.co/t/kibana-timeout-but-curl-with-same-query-works-perfectly/258405/4 "2020-12-11T13:28:25Z")

</div>

Hi thanks for response, but if it were one parameter it would fail also for the curl or for any timestamp but with 30 days works perfectly ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2021, 1:28pm UTC](https://discuss.elastic.co/t/kibana-timeout-but-curl-with-same-query-works-perfectly/258405/5 "2021-01-08T13:28:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
