# Loading field caused out of memory failure

**URL:** https://discuss.elastic.co/t/loading-field-caused-out-of-memory-failure/11546
**Category:** Elasticsearch
**Created:** [April 11, 2013, 10:46am UTC](https://discuss.elastic.co/t/loading-field-caused-out-of-memory-failure/11546 "2013-04-11T10:46:35Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Matthieu](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@Matthieu](https://discuss.elastic.co/u/Matthieu)
#### Post date: [April 11, 2013, 10:46am UTC](https://discuss.elastic.co/t/loading-field-caused-out-of-memory-failure/11546/1 "2013-04-11T10:46:35Z")

</div>

Hi,

I've a strange failure on my ES cluster. I've 3 nodes with a daily index(4  
actually) to store server's logs. When I execute this query:

{"query" : {"match\_all" : {}},"facets" : {"Logs" : {"terms" : {"field" :  
"tag","size" : 10, "order" : "term"}}}}

I've a succesfull answer. But I would modify the query and replace "tag" by  
this field name "req\_url". When I perform this query, I've a timeout error  
and if I check my ES logs in a node, I can see that:

[2013-04-11 12:17:21,330][WARN][index.cache.field.data.soft]  
[mor-elasticsearch-02] [logs-2013.04.10] loading field [req\_url] caused out  
of memory failure  
java.lang.OutOfMemoryError: Java heap space  
[2013-04-11 12:17:21,349][WARN][index.cache.field.data.soft]  
[mor-elasticsearch-02] [logs-2013.04.10] loading field [req\_url] caused out  
of memory failure  
java.lang.OutOfMemoryError: Java heap space

And on another node I've these logs:

[2013-04-11 12:14:43,398][DEBUG][action.admin.indices.stats]  
[mor-elasticsearch-03] [logs-2013.04.10][1], node[f6aKvGEVR7CyJ7G-o3WsGA],  
[R], s[STARTED]: Failed to execute  
[org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
org.elasticsearch.transport.NodeDisconnectedException:  
[mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
disconnected  
[2013-04-11 12:14:43,398][DEBUG][action.admin.indices.stats]  
[mor-elasticsearch-03] [logs-2013.04.08][2], node[f6aKvGEVR7CyJ7G-o3WsGA],  
[R], s[STARTED]: Failed to execute  
[org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
org.elasticsearch.transport.NodeDisconnectedException:  
[mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
disconnected  
[2013-04-11 12:14:43,399][DEBUG][action.admin.indices.stats]  
[mor-elasticsearch-03] [logs-2013.04.10][0], node[f6aKvGEVR7CyJ7G-o3WsGA],  
[R], s[STARTED]: Failed to execute  
[org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
org.elasticsearch.transport.NodeDisconnectedException:  
[mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
disconnected  
[2013-04-11 12:14:43,401][DEBUG][action.admin.indices.stats]  
[mor-elasticsearch-03] [logs-2013.04.10][2], node[f6aKvGEVR7CyJ7G-o3WsGA],  
[R], s[STARTED]: Failed to execute  
[org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
org.elasticsearch.transport.NodeDisconnectedException:  
[mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
disconnected  
[2013-04-11 12:14:43,402][DEBUG][action.admin.indices.stats]  
[mor-elasticsearch-03] [logs-2013.04.10][3], node[f6aKvGEVR7CyJ7G-o3WsGA],  
[P], s[STARTED]: Failed to execute  
[org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
org.elasticsearch.transport.NodeDisconnectedException:  
[mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
disconnected

[2013-04-11 12:22:04,527][WARN][cluster.action.shard]  
[mor-elasticsearch-01] received shard failed for [logs-2013.04.08][1],  
node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
[mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
marked shard as started, but shard have not been created, mark shard as  
failed]  
[2013-04-11 12:22:04,528][WARN][cluster.action.shard]  
[mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
[mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
marked shard as started, but shard have not been created, mark shard as  
failed]  
[2013-04-11 12:22:04,843][WARN][cluster.action.shard]  
[mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
[mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
marked shard as started, but shard have not been created, mark shard as  
failed]  
[2013-04-11 12:22:04,844][WARN][cluster.action.shard]  
[mor-elasticsearch-01] received shard failed for [logs-2013.04.08][1],  
node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
[mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
marked shard as started, but shard have not been created, mark shard as  
failed]  
[2013-04-11 12:22:04,846][WARN][cluster.action.shard]  
[mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
[mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
marked shard as started, but shard have not been created, mark shard as  
failed]  
[2013-04-11 12:22:05,173][WARN][cluster.action.shard]  
[mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
[mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
marked shard as started, but shard have not been created, mark shard as  
failed]  
[2013-04-11 12:22:05,174][WARN][cluster.action.shard]  
[mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
[mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
marked shard as started, but shard have not been created, mark shard as  
failed]  
[2013-04-11 12:22:05,376][WARN][cluster.action.shard]  
[mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
[mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
marked shard as started, but shard have not been created, mark shard as  
failed]

The status of my ES cluster became Red. I'm beginner in the ES world, it's  
possible that I perform a bad request but I find the impact very huge!

Thanks in advance

Matthieu

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![mvg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvg/32/98890_2.png) [@mvg](https://discuss.elastic.co/u/mvg)
#### Post date: [April 11, 2013, 1:07pm UTC](https://discuss.elastic.co/t/loading-field-caused-out-of-memory-failure/11546/2 "2013-04-11T13:07:03Z")

</div>

Yes, the impact of performing a search request on a new facet field if  
there is not enough memory is big. You have ran out of Java heap space. You  
need to increase it and you can do this via the ES\_HEAP\_SIZE environment  
variable. This env variable is set to 1GB by default. I'd double it and see  
if it is sufficient. In any case don't set it higher than ~half of your  
available RAM.

I also recommend setting up warming queries. Configure warming queries that  
facet / sort on all the field your users would use. This way you find out  
that you don't have enough memory at startup. Also when using warming  
queries your users won't notice when field values are loaded in memory,  
since this would happen as part of the refresh and not as part of the  
search.

On 11 April 2013 12:46, Matthieu [mboret86@gmail.com](mailto:mboret86@gmail.com) wrote:

> Hi,
> 
> I've a strange failure on my ES cluster. I've 3 nodes with a daily index(4  
> actually) to store server's logs. When I execute this query:
> 
> {"query" : {"match\_all" : {}},"facets" : {"Logs" : {"terms" : {"field" :  
> "tag","size" : 10, "order" : "term"}}}}
> 
> I've a succesfull answer. But I would modify the query and replace "tag"  
> by this field name "req\_url". When I perform this query, I've a timeout  
> error and if I check my ES logs in a node, I can see that:
> 
> [2013-04-11 12:17:21,330][WARN][index.cache.field.data.soft]  
> [mor-elasticsearch-02] [logs-2013.04.10] loading field [req\_url] caused out  
> of memory failure  
> java.lang.OutOfMemoryError: Java heap space  
> [2013-04-11 12:17:21,349][WARN][index.cache.field.data.soft]  
> [mor-elasticsearch-02] [logs-2013.04.10] loading field [req\_url] caused out  
> of memory failure  
> java.lang.OutOfMemoryError: Java heap space
> 
> And on another node I've these logs:
> 
> [2013-04-11 12:14:43,398][DEBUG][action.admin.indices.stats]  
> [mor-elasticsearch-03] [logs-2013.04.10][1], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> [R], s[STARTED]: Failed to execute  
> [org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
> org.elasticsearch.transport.NodeDisconnectedException:  
> [mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
> disconnected  
> [2013-04-11 12:14:43,398][DEBUG][action.admin.indices.stats]  
> [mor-elasticsearch-03] [logs-2013.04.08][2], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> [R], s[STARTED]: Failed to execute  
> [org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
> org.elasticsearch.transport.NodeDisconnectedException:  
> [mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
> disconnected  
> [2013-04-11 12:14:43,399][DEBUG][action.admin.indices.stats]  
> [mor-elasticsearch-03] [logs-2013.04.10][0], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> [R], s[STARTED]: Failed to execute  
> [org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
> org.elasticsearch.transport.NodeDisconnectedException:  
> [mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
> disconnected  
> [2013-04-11 12:14:43,401][DEBUG][action.admin.indices.stats]  
> [mor-elasticsearch-03] [logs-2013.04.10][2], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> [R], s[STARTED]: Failed to execute  
> [org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
> org.elasticsearch.transport.NodeDisconnectedException:  
> [mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
> disconnected  
> [2013-04-11 12:14:43,402][DEBUG][action.admin.indices.stats]  
> [mor-elasticsearch-03] [logs-2013.04.10][3], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> [P], s[STARTED]: Failed to execute  
> [org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
> org.elasticsearch.transport.NodeDisconnectedException:  
> [mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
> disconnected
> 
> [2013-04-11 12:22:04,527][WARN][cluster.action.shard]  
> [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][1],  
> node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> marked shard as started, but shard have not been created, mark shard as  
> failed]  
> [2013-04-11 12:22:04,528][WARN][cluster.action.shard]  
> [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> marked shard as started, but shard have not been created, mark shard as  
> failed]  
> [2013-04-11 12:22:04,843][WARN][cluster.action.shard]  
> [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> marked shard as started, but shard have not been created, mark shard as  
> failed]  
> [2013-04-11 12:22:04,844][WARN][cluster.action.shard]  
> [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][1],  
> node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> marked shard as started, but shard have not been created, mark shard as  
> failed]  
> [2013-04-11 12:22:04,846][WARN][cluster.action.shard]  
> [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> marked shard as started, but shard have not been created, mark shard as  
> failed]  
> [2013-04-11 12:22:05,173][WARN][cluster.action.shard]  
> [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> marked shard as started, but shard have not been created, mark shard as  
> failed]  
> [2013-04-11 12:22:05,174][WARN][cluster.action.shard]  
> [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> marked shard as started, but shard have not been created, mark shard as  
> failed]  
> [2013-04-11 12:22:05,376][WARN][cluster.action.shard]  
> [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> marked shard as started, but shard have not been created, mark shard as  
> failed]
> 
> The status of my ES cluster became Red. I'm beginner in the ES world, it's  
> possible that I perform a bad request but I find the impact very huge!
> 
> Thanks in advance
> 
> Matthieu
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Met vriendelijke groet,

Martijn van Groningen

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![Matthieu](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@Matthieu](https://discuss.elastic.co/u/Matthieu)
#### Post date: [April 11, 2013, 2:34pm UTC](https://discuss.elastic.co/t/loading-field-caused-out-of-memory-failure/11546/3 "2013-04-11T14:34:30Z")

</div>

Hi Martijin,

Thanks a lot for your answer. You're right Java doesn't start with the  
value ES\_MIN\_MEM and ES\_MAX\_MEM which have been setup in the eleasticsearch  
init.d. I've correct this error and this avoid my OOM failure.  
But can you give me more informations about your warning query? It's the  
same that warm-up query for solr?

Thanks

Matthieu

On Thursday, April 11, 2013 3:07:03 PM UTC+2, Martijn v Groningen wrote:

> Yes, the impact of performing a search request on a new facet field if  
> there is not enough memory is big. You have ran out of Java heap space. You  
> need to increase it and you can do this via the ES\_HEAP\_SIZE environment  
> variable. This env variable is set to 1GB by default. I'd double it and see  
> if it is sufficient. In any case don't set it higher than ~half of your  
> available RAM.
> 
> I also recommend setting up warming queries. Configure warming queries  
> that facet / sort on all the field your users would use. This way you find  
> out that you don't have enough memory at startup. Also when using warming  
> queries your users won't notice when field values are loaded in memory,  
> since this would happen as part of the refresh and not as part of the  
> search.
> 
> On 11 April 2013 12:46, Matthieu \<[mbor...@gmail.com](mailto:mbor...@gmail.com) \<javascript:\>\> wrote:
> 
> > Hi,
> > 
> > I've a strange failure on my ES cluster. I've 3 nodes with a daily  
> > index(4 actually) to store server's logs. When I execute this query:
> > 
> > {"query" : {"match\_all" : {}},"facets" : {"Logs" : {"terms" : {"field" :  
> > "tag","size" : 10, "order" : "term"}}}}
> > 
> > I've a succesfull answer. But I would modify the query and replace "tag"  
> > by this field name "req\_url". When I perform this query, I've a timeout  
> > error and if I check my ES logs in a node, I can see that:
> > 
> > [2013-04-11 12:17:21,330][WARN][index.cache.field.data.soft]  
> > [mor-elasticsearch-02] [logs-2013.04.10] loading field [req\_url] caused out  
> > of memory failure  
> > java.lang.OutOfMemoryError: Java heap space  
> > [2013-04-11 12:17:21,349][WARN][index.cache.field.data.soft]  
> > [mor-elasticsearch-02] [logs-2013.04.10] loading field [req\_url] caused out  
> > of memory failure  
> > java.lang.OutOfMemoryError: Java heap space
> > 
> > And on another node I've these logs:
> > 
> > [2013-04-11 12:14:43,398][DEBUG][action.admin.indices.stats]  
> > [mor-elasticsearch-03] [logs-2013.04.10][1], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > [R], s[STARTED]: Failed to execute  
> > [org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
> > org.elasticsearch.transport.NodeDisconnectedException:  
> > [mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
> > disconnected  
> > [2013-04-11 12:14:43,398][DEBUG][action.admin.indices.stats]  
> > [mor-elasticsearch-03] [logs-2013.04.08][2], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > [R], s[STARTED]: Failed to execute  
> > [org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
> > org.elasticsearch.transport.NodeDisconnectedException:  
> > [mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
> > disconnected  
> > [2013-04-11 12:14:43,399][DEBUG][action.admin.indices.stats]  
> > [mor-elasticsearch-03] [logs-2013.04.10][0], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > [R], s[STARTED]: Failed to execute  
> > [org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
> > org.elasticsearch.transport.NodeDisconnectedException:  
> > [mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
> > disconnected  
> > [2013-04-11 12:14:43,401][DEBUG][action.admin.indices.stats]  
> > [mor-elasticsearch-03] [logs-2013.04.10][2], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > [R], s[STARTED]: Failed to execute  
> > [org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
> > org.elasticsearch.transport.NodeDisconnectedException:  
> > [mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
> > disconnected  
> > [2013-04-11 12:14:43,402][DEBUG][action.admin.indices.stats]  
> > [mor-elasticsearch-03] [logs-2013.04.10][3], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > [P], s[STARTED]: Failed to execute  
> > [org.elasticsearch.action.admin.indices.stats.IndicesStatsRequest@6eee124]  
> > org.elasticsearch.transport.NodeDisconnectedException:  
> > [mor-elasticsearch-02][inet[/192.168.245.100:9301]][indices/stats/s]  
> > disconnected
> > 
> > [2013-04-11 12:22:04,527][WARN][cluster.action.shard]  
> > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][1],  
> > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> > marked shard as started, but shard have not been created, mark shard as  
> > failed]  
> > [2013-04-11 12:22:04,528][WARN][cluster.action.shard]  
> > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> > marked shard as started, but shard have not been created, mark shard as  
> > failed]  
> > [2013-04-11 12:22:04,843][WARN][cluster.action.shard]  
> > [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> > node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> > [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> > marked shard as started, but shard have not been created, mark shard as  
> > failed]  
> > [2013-04-11 12:22:04,844][WARN][cluster.action.shard]  
> > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][1],  
> > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> > marked shard as started, but shard have not been created, mark shard as  
> > failed]  
> > [2013-04-11 12:22:04,846][WARN][cluster.action.shard]  
> > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> > marked shard as started, but shard have not been created, mark shard as  
> > failed]  
> > [2013-04-11 12:22:05,173][WARN][cluster.action.shard]  
> > [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> > node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> > [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> > marked shard as started, but shard have not been created, mark shard as  
> > failed]  
> > [2013-04-11 12:22:05,174][WARN][cluster.action.shard]  
> > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> > marked shard as started, but shard have not been created, mark shard as  
> > failed]  
> > [2013-04-11 12:22:05,376][WARN][cluster.action.shard]  
> > [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> > node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> > [mor-elasticsearch-01][DdmTythfSo25UkWPcWgxAg][inet[/192.168.245.99:9300]]  
> > marked shard as started, but shard have not been created, mark shard as  
> > failed]
> > 
> > The status of my ES cluster became Red. I'm beginner in the ES world,  
> > it's possible that I perform a bad request but I find the impact very huge!
> > 
> > Thanks in advance
> > 
> > Matthieu
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> Met vriendelijke groet,
> 
> Martijn van Groningen

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![mvg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvg/32/98890_2.png) [@mvg](https://discuss.elastic.co/u/mvg)
#### Post date: [April 11, 2013, 2:52pm UTC](https://discuss.elastic.co/t/loading-field-caused-out-of-memory-failure/11546/4 "2013-04-11T14:52:55Z")

</div>

The warming api is similar to Solr's warmup query.  
The warming api's documentation page describes how your can use it:

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

On 11 April 2013 16:34, Matthieu [mboret86@gmail.com](mailto:mboret86@gmail.com) wrote:

> Hi Martijin,
> 
> Thanks a lot for your answer. You're right Java doesn't start with the  
> value ES\_MIN\_MEM and ES\_MAX\_MEM which have been setup in the eleasticsearch  
> init.d. I've correct this error and this avoid my OOM failure.  
> But can you give me more informations about your warning query? It's the  
> same that warm-up query for solr?
> 
> Thanks
> 
> Matthieu
> 
> On Thursday, April 11, 2013 3:07:03 PM UTC+2, Martijn v Groningen wrote:
> 
> > Yes, the impact of performing a search request on a new facet field if  
> > there is not enough memory is big. You have ran out of Java heap space. You  
> > need to increase it and you can do this via the ES\_HEAP\_SIZE environment  
> > variable. This env variable is set to 1GB by default. I'd double it and see  
> > if it is sufficient. In any case don't set it higher than ~half of your  
> > available RAM.
> > 
> > I also recommend setting up warming queries. Configure warming queries  
> > that facet / sort on all the field your users would use. This way you find  
> > out that you don't have enough memory at startup. Also when using warming  
> > queries your users won't notice when field values are loaded in memory,  
> > since this would happen as part of the refresh and not as part of the  
> > search.
> > 
> > On 11 April 2013 12:46, Matthieu [mbor...@gmail.com](mailto:mbor...@gmail.com) wrote:
> > 
> > > Hi,
> > > 
> > > I've a strange failure on my ES cluster. I've 3 nodes with a daily  
> > > index(4 actually) to store server's logs. When I execute this query:
> > > 
> > > {"query" : {"match\_all" : {}},"facets" : {"Logs" : {"terms" : {"field" :  
> > > "tag","size" : 10, "order" : "term"}}}}
> > > 
> > > I've a succesfull answer. But I would modify the query and replace "tag"  
> > > by this field name "req\_url". When I perform this query, I've a timeout  
> > > error and if I check my ES logs in a node, I can see that:
> > > 
> > > [2013-04-11 12:17:21,330][WARN][index.cache.field.data.soft]  
> > > [mor-elasticsearch-02] [logs-2013.04.10] loading field [req\_url] caused out  
> > > of memory failure  
> > > java.lang.OutOfMemoryError: Java heap space  
> > > [2013-04-11 12:17:21,349][WARN][index.cache.field.data.soft]  
> > > [mor-elasticsearch-02] [logs-2013.04.10] loading field [req\_url] caused out  
> > > of memory failure  
> > > java.lang.OutOfMemoryError: Java heap space
> > > 
> > > And on another node I've these logs:
> > > 
> > > [2013-04-11 12:14:43,398][DEBUG][action.**admin.indices.stats]  
> > > [mor-elasticsearch-03] [logs-2013.04.10][1], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > > [R], s[STARTED]: Failed to execute [org.elasticsearch.action.**  
> > > admin.indices.stats.\*\*IndicesStatsRequest@6eee124]  
> > > org.elasticsearch.transport.\*\*NodeDisconnectedException:  
> > > [mor-elasticsearch-02][inet[/\*\*192.168.245.100:9301]][\*\*indices/stats/s]  
> > > disconnected  
> > > [2013-04-11 12:14:43,398][DEBUG][action.**admin.indices.stats]  
> > > [mor-elasticsearch-03] [logs-2013.04.08][2], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > > [R], s[STARTED]: Failed to execute [org.elasticsearch.action.**  
> > > admin.indices.stats.\*\*IndicesStatsRequest@6eee124]  
> > > org.elasticsearch.transport.\*\*NodeDisconnectedException:  
> > > [mor-elasticsearch-02][inet[/\*\*192.168.245.100:9301]][\*\*indices/stats/s]  
> > > disconnected  
> > > [2013-04-11 12:14:43,399][DEBUG][action.**admin.indices.stats]  
> > > [mor-elasticsearch-03] [logs-2013.04.10][0], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > > [R], s[STARTED]: Failed to execute [org.elasticsearch.action.**  
> > > admin.indices.stats.\*\*IndicesStatsRequest@6eee124]  
> > > org.elasticsearch.transport.\*\*NodeDisconnectedException:  
> > > [mor-elasticsearch-02][inet[/\*\*192.168.245.100:9301]][\*\*indices/stats/s]  
> > > disconnected  
> > > [2013-04-11 12:14:43,401][DEBUG][action.**admin.indices.stats]  
> > > [mor-elasticsearch-03] [logs-2013.04.10][2], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > > [R], s[STARTED]: Failed to execute [org.elasticsearch.action.**  
> > > admin.indices.stats.\*\*IndicesStatsRequest@6eee124]  
> > > org.elasticsearch.transport.\*\*NodeDisconnectedException:  
> > > [mor-elasticsearch-02][inet[/\*\*192.168.245.100:9301]][\*\*indices/stats/s]  
> > > disconnected  
> > > [2013-04-11 12:14:43,402][DEBUG][action.**admin.indices.stats]  
> > > [mor-elasticsearch-03] [logs-2013.04.10][3], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > > [P], s[STARTED]: Failed to execute [org.elasticsearch.action.**  
> > > admin.indices.stats.\*\*IndicesStatsRequest@6eee124]  
> > > org.elasticsearch.transport.\*\*NodeDisconnectedException:  
> > > [mor-elasticsearch-02][inet[/\*\*192.168.245.100:9301]][\*\*indices/stats/s]  
> > > disconnected
> > > 
> > > [2013-04-11 12:22:04,527][WARN][cluster.action.shard]  
> > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][1],  
> > > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > started, but shard have not been created, mark shard as failed]  
> > > [2013-04-11 12:22:04,528][WARN][cluster.action.shard]  
> > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> > > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > started, but shard have not been created, mark shard as failed]  
> > > [2013-04-11 12:22:04,843][WARN][cluster.action.shard]  
> > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> > > node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > started, but shard have not been created, mark shard as failed]  
> > > [2013-04-11 12:22:04,844][WARN][cluster.action.shard]  
> > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][1],  
> > > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > started, but shard have not been created, mark shard as failed]  
> > > [2013-04-11 12:22:04,846][WARN][cluster.action.shard]  
> > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> > > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > started, but shard have not been created, mark shard as failed]  
> > > [2013-04-11 12:22:05,173][WARN][cluster.action.shard]  
> > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> > > node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > started, but shard have not been created, mark shard as failed]  
> > > [2013-04-11 12:22:05,174][WARN][cluster.action.shard]  
> > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> > > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > started, but shard have not been created, mark shard as failed]  
> > > [2013-04-11 12:22:05,376][WARN][cluster.action.shard]  
> > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> > > node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > started, but shard have not been created, mark shard as failed]
> > > 
> > > The status of my ES cluster became Red. I'm beginner in the ES world,  
> > > it's possible that I perform a bad request but I find the impact very huge!
> > > 
> > > Thanks in advance
> > > 
> > > Matthieu
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to elasticsearc...@\*\*[googlegroups.com](http://googlegroups.com).
> > > 
> > > For more options, visit [https://groups.google.com/\*\*groups/opt\_out](https://groups.google.com/**groups/opt_out)[https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out)  
> > > .
> > 
> > --  
> > Met vriendelijke groet,
> > 
> > Martijn van Groningen

--  
Met vriendelijke groet,

Martijn van Groningen

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![Matthieu](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@Matthieu](https://discuss.elastic.co/u/Matthieu)
#### Post date: [April 11, 2013, 3:24pm UTC](https://discuss.elastic.co/t/loading-field-caused-out-of-memory-failure/11546/5 "2013-04-11T15:24:05Z")

</div>

Ok, Thanks for all Martijn.

Matthieu

On Thursday, April 11, 2013 4:52:55 PM UTC+2, Martijn v Groningen wrote:

> The warming api is similar to Solr's warmup query.  
> The warming api's documentation page describes how your can use it:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/api/admin-indices-warmers/)
> 
> On 11 April 2013 16:34, Matthieu \<[mbor...@gmail.com](mailto:mbor...@gmail.com) \<javascript:\>\> wrote:
> 
> > Hi Martijin,
> > 
> > Thanks a lot for your answer. You're right Java doesn't start with the  
> > value ES\_MIN\_MEM and ES\_MAX\_MEM which have been setup in the eleasticsearch  
> > init.d. I've correct this error and this avoid my OOM failure.  
> > But can you give me more informations about your warning query? It's the  
> > same that warm-up query for solr?
> > 
> > Thanks
> > 
> > Matthieu
> > 
> > On Thursday, April 11, 2013 3:07:03 PM UTC+2, Martijn v Groningen wrote:
> > 
> > > Yes, the impact of performing a search request on a new facet field if  
> > > there is not enough memory is big. You have ran out of Java heap space. You  
> > > need to increase it and you can do this via the ES\_HEAP\_SIZE environment  
> > > variable. This env variable is set to 1GB by default. I'd double it and see  
> > > if it is sufficient. In any case don't set it higher than ~half of your  
> > > available RAM.
> > > 
> > > I also recommend setting up warming queries. Configure warming queries  
> > > that facet / sort on all the field your users would use. This way you find  
> > > out that you don't have enough memory at startup. Also when using warming  
> > > queries your users won't notice when field values are loaded in memory,  
> > > since this would happen as part of the refresh and not as part of the  
> > > search.
> > > 
> > > On 11 April 2013 12:46, Matthieu [mbor...@gmail.com](mailto:mbor...@gmail.com) wrote:
> > > 
> > > > Hi,
> > > > 
> > > > I've a strange failure on my ES cluster. I've 3 nodes with a daily  
> > > > index(4 actually) to store server's logs. When I execute this query:
> > > > 
> > > > {"query" : {"match\_all" : {}},"facets" : {"Logs" : {"terms" : {"field"  
> > > > : "tag","size" : 10, "order" : "term"}}}}
> > > > 
> > > > I've a succesfull answer. But I would modify the query and replace  
> > > > "tag" by this field name "req\_url". When I perform this query, I've a  
> > > > timeout error and if I check my ES logs in a node, I can see that:
> > > > 
> > > > [2013-04-11 12:17:21,330][WARN][index.cache.field.data.soft]  
> > > > [mor-elasticsearch-02] [logs-2013.04.10] loading field [req\_url] caused out  
> > > > of memory failure  
> > > > java.lang.OutOfMemoryError: Java heap space  
> > > > [2013-04-11 12:17:21,349][WARN][index.cache.field.data.soft]  
> > > > [mor-elasticsearch-02] [logs-2013.04.10] loading field [req\_url] caused out  
> > > > of memory failure  
> > > > java.lang.OutOfMemoryError: Java heap space
> > > > 
> > > > And on another node I've these logs:
> > > > 
> > > > [2013-04-11 12:14:43,398][DEBUG][action.**admin.indices.stats]  
> > > > [mor-elasticsearch-03] [logs-2013.04.10][1], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > > > [R], s[STARTED]: Failed to execute [org.elasticsearch.action.**  
> > > > admin.indices.stats.\*\*IndicesStatsRequest@6eee124]  
> > > > org.elasticsearch.transport.\*\*NodeDisconnectedException:  
> > > > [mor-elasticsearch-02][inet[/\*\*192.168.245.100:9301]][\*\*indices/stats/s]  
> > > > disconnected  
> > > > [2013-04-11 12:14:43,398][DEBUG][action.**admin.indices.stats]  
> > > > [mor-elasticsearch-03] [logs-2013.04.08][2], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > > > [R], s[STARTED]: Failed to execute [org.elasticsearch.action.**  
> > > > admin.indices.stats.\*\*IndicesStatsRequest@6eee124]  
> > > > org.elasticsearch.transport.\*\*NodeDisconnectedException:  
> > > > [mor-elasticsearch-02][inet[/\*\*192.168.245.100:9301]][\*\*indices/stats/s]  
> > > > disconnected  
> > > > [2013-04-11 12:14:43,399][DEBUG][action.**admin.indices.stats]  
> > > > [mor-elasticsearch-03] [logs-2013.04.10][0], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > > > [R], s[STARTED]: Failed to execute [org.elasticsearch.action.**  
> > > > admin.indices.stats.\*\*IndicesStatsRequest@6eee124]  
> > > > org.elasticsearch.transport.\*\*NodeDisconnectedException:  
> > > > [mor-elasticsearch-02][inet[/\*\*192.168.245.100:9301]][\*\*indices/stats/s]  
> > > > disconnected  
> > > > [2013-04-11 12:14:43,401][DEBUG][action.**admin.indices.stats]  
> > > > [mor-elasticsearch-03] [logs-2013.04.10][2], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > > > [R], s[STARTED]: Failed to execute [org.elasticsearch.action.**  
> > > > admin.indices.stats.\*\*IndicesStatsRequest@6eee124]  
> > > > org.elasticsearch.transport.\*\*NodeDisconnectedException:  
> > > > [mor-elasticsearch-02][inet[/\*\*192.168.245.100:9301]][\*\*indices/stats/s]  
> > > > disconnected  
> > > > [2013-04-11 12:14:43,402][DEBUG][action.**admin.indices.stats]  
> > > > [mor-elasticsearch-03] [logs-2013.04.10][3], node[f6aKvGEVR7CyJ7G-o3WsGA],  
> > > > [P], s[STARTED]: Failed to execute [org.elasticsearch.action.**  
> > > > admin.indices.stats.\*\*IndicesStatsRequest@6eee124]  
> > > > org.elasticsearch.transport.\*\*NodeDisconnectedException:  
> > > > [mor-elasticsearch-02][inet[/\*\*192.168.245.100:9301]][\*\*indices/stats/s]  
> > > > disconnected
> > > > 
> > > > [2013-04-11 12:22:04,527][WARN][cluster.action.shard]  
> > > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][1],  
> > > > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > > started, but shard have not been created, mark shard as failed]  
> > > > [2013-04-11 12:22:04,528][WARN][cluster.action.shard]  
> > > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> > > > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > > started, but shard have not been created, mark shard as failed]  
> > > > [2013-04-11 12:22:04,843][WARN][cluster.action.shard]  
> > > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> > > > node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> > > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > > started, but shard have not been created, mark shard as failed]  
> > > > [2013-04-11 12:22:04,844][WARN][cluster.action.shard]  
> > > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][1],  
> > > > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > > started, but shard have not been created, mark shard as failed]  
> > > > [2013-04-11 12:22:04,846][WARN][cluster.action.shard]  
> > > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> > > > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > > started, but shard have not been created, mark shard as failed]  
> > > > [2013-04-11 12:22:05,173][WARN][cluster.action.shard]  
> > > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> > > > node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> > > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > > started, but shard have not been created, mark shard as failed]  
> > > > [2013-04-11 12:22:05,174][WARN][cluster.action.shard]  
> > > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.08][3],  
> > > > node[nYV56WwyQPaAwZW7bORM4A], [P], s[STARTED], reason [master  
> > > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > > started, but shard have not been created, mark shard as failed]  
> > > > [2013-04-11 12:22:05,376][WARN][cluster.action.shard]  
> > > > [mor-elasticsearch-01] received shard failed for [logs-2013.04.09][4],  
> > > > node[nYV56WwyQPaAwZW7bORM4A], [R], s[STARTED], reason [master  
> > > > [mor-elasticsearch-01][**DdmTythfSo25UkWPcWgxAg][inet[/**  
> > > > 192.168.245.99:9300 [http://192.168.245.99:9300](http://192.168.245.99:9300)]] marked shard as  
> > > > started, but shard have not been created, mark shard as failed]
> > > > 
> > > > The status of my ES cluster became Red. I'm beginner in the ES world,  
> > > > it's possible that I perform a bad request but I find the impact very huge!
> > > > 
> > > > Thanks in advance
> > > > 
> > > > Matthieu
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google  
> > > > Groups "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > an email to elasticsearc...@\*\*[googlegroups.com](http://googlegroups.com).
> > > > 
> > > > For more options, visit [https://groups.google.com/\*\*groups/opt\_out](https://groups.google.com/**groups/opt_out)[https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out)  
> > > > .
> > > 
> > > --  
> > > Met vriendelijke groet,
> > > 
> > > Martijn van Groningen
> 
> --  
> Met vriendelijke groet,
> 
> Martijn van Groningen

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 2:41am UTC](https://discuss.elastic.co/t/loading-field-caused-out-of-memory-failure/11546/6 "2017-07-06T02:41:31Z")

</div>


