# Many indices.fielddata.breaker errors in logs and cluster slow

**URL:** <https://discuss.elastic.co/t/many-indices-fielddata-breaker-errors-in-logs-and-cluster-slow/20112>\
**Category:** Elasticsearch\
**Created:** [October 7, 2014, 12:29pm UTC](https://discuss.elastic.co/t/many-indices-fielddata-breaker-errors-in-logs-and-cluster-slow/20112 "2014-10-07T12:29:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robin\_Clarke](https://avatars.discourse-cdn.com/v4/letter/r/7ba0ec/32.png) [@Robin\_Clarke](https://discuss.elastic.co/u/Robin_Clarke)\
**Post date:** [October 7, 2014, 12:29pm UTC](https://discuss.elastic.co/t/many-indices-fielddata-breaker-errors-in-logs-and-cluster-slow/20112/1 "2014-10-07T12:29:22Z")

</div>

I'm getting a lot of these errors in my Elasticsearch logs, and am also  
experiencing a lot of slowness on the cluster...

New used memory 7670582710 [7.1gb] from field [machineName.raw] would be  
larger than configured breaker: 7666532352 [7.1gb], breaking  
...  
New used memory 7674188379 [7.1gb] from field [@timestamp] would be larger  
than configured breaker: 7666532352 [7.1gb], breaking

I've looked at the documentation about memory limits  
[http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/\_limiting\_memory\_usage.html](http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/_limiting_memory_usage.html),  
but I don't really understand what is causing this, and more importantly  
how to avoid this...

My cluster is 10 machines @ 32GB memory and 8 CPU cores each. I have one  
ES node on each machine with 12GB memory allocated. On each machine there  
is additionally one logstash agent (1GB) and one redis server (2GB).  
I have 10 indexes open with one replication per shard (so each node should  
only be holding 22 shards (two more for kibana-int)).

I'm using Elasticsearch 1.3.3, Logstash 1.4.2

Thanks for your help!

-Robin-

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0f553ebc-12a5-402c-82cb-9751fde111eb%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0f553ebc-12a5-402c-82cb-9751fde111eb%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Robin\_Clarke](https://avatars.discourse-cdn.com/v4/letter/r/7ba0ec/32.png) [@Robin\_Clarke](https://discuss.elastic.co/u/Robin_Clarke)\
**Post date:** [October 16, 2014, 5:42am UTC](https://discuss.elastic.co/t/many-indices-fielddata-breaker-errors-in-logs-and-cluster-slow/20112/2 "2014-10-16T05:42:54Z")

</div>

I'm still having this problem... has anybody got an idea what the cause /  
solution might be?

Thank you! 🙂

On Tuesday, 7 October 2014 14:29:22 UTC+2, Robin Clarke wrote:

> I'm getting a lot of these errors in my Elasticsearch logs, and am also  
> experiencing a lot of slowness on the cluster...
> 
> New used memory 7670582710 [7.1gb] from field [machineName.raw] would be  
> larger than configured breaker: 7666532352 [7.1gb], breaking  
> ...  
> New used memory 7674188379 [7.1gb] from field [@timestamp] would be larger  
> than configured breaker: 7666532352 [7.1gb], breaking
> 
> I've looked at the documentation about memory limits  
> [http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/\_limiting\_memory\_usage.html](http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/_limiting_memory_usage.html),  
> but I don't really understand what is causing this, and more importantly  
> how to avoid this...
> 
> My cluster is 10 machines @ 32GB memory and 8 CPU cores each. I have one  
> ES node on each machine with 12GB memory allocated. On each machine there  
> is additionally one logstash agent (1GB) and one redis server (2GB).  
> I have 10 indexes open with one replication per shard (so each node should  
> only be holding 22 shards (two more for kibana-int)).
> 
> I'm using Elasticsearch 1.3.3, Logstash 1.4.2
> 
> Thanks for your help!
> 
> -Robin-

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5935b1f4-809c-46ac-ba03-f1df33a8737e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5935b1f4-809c-46ac-ba03-f1df33a8737e%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Kimbro\_Staken](https://avatars.discourse-cdn.com/v4/letter/k/9fc29f/32.png) [@Kimbro\_Staken](https://discuss.elastic.co/u/Kimbro_Staken)\
**Post date:** [October 16, 2014, 4:33pm UTC](https://discuss.elastic.co/t/many-indices-fielddata-breaker-errors-in-logs-and-cluster-slow/20112/3 "2014-10-16T16:33:56Z")

</div>

This is caused by elasticsearch trying to load fielddata. Fielddata is used  
for sorting and faceting/aggregations. When a query has a sort parameter  
the node will try to load the fielddata for that field for all documents in  
the shard, not just those included in the query result. The breaker is  
tripped when ES estimates there is not enough heap available to load the  
fielddata so it just rejects the query rather than running the node out of  
heap space.

You should probably start by looking at the queries that are being run to  
determine what's triggering the error. To deal with it the options I'm  
aware of are to add heap space, more nodes or look at using doc\_values to  
move fielddata off the heap.

Kimbro

On Wed, Oct 15, 2014 at 10:42 PM, Robin Clarke [robin13@gmail.com](mailto:robin13@gmail.com) wrote:

> I'm still having this problem... has anybody got an idea what the cause /  
> solution might be?
> 
> Thank you! 🙂
> 
> On Tuesday, 7 October 2014 14:29:22 UTC+2, Robin Clarke wrote:
> 
> > I'm getting a lot of these errors in my Elasticsearch logs, and am also  
> > experiencing a lot of slowness on the cluster...
> > 
> > New used memory 7670582710 [7.1gb] from field [machineName.raw] would be  
> > larger than configured breaker: 7666532352 [7.1gb], breaking  
> > ...  
> > New used memory 7674188379 [7.1gb] from field [@timestamp] would be  
> > larger than configured breaker: 7666532352 [7.1gb], breaking
> > 
> > I've looked at the documentation about memory limits  
> > [http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/\_limiting\_memory\_usage.html](http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/_limiting_memory_usage.html),  
> > but I don't really understand what is causing this, and more importantly  
> > how to avoid this...
> > 
> > My cluster is 10 machines @ 32GB memory and 8 CPU cores each. I have one  
> > ES node on each machine with 12GB memory allocated. On each machine there  
> > is additionally one logstash agent (1GB) and one redis server (2GB).  
> > I have 10 indexes open with one replication per shard (so each node  
> > should only be holding 22 shards (two more for kibana-int)).
> > 
> > I'm using Elasticsearch 1.3.3, Logstash 1.4.2
> > 
> > Thanks for your help!
> > 
> > -Robin-
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/5935b1f4-809c-46ac-ba03-f1df33a8737e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5935b1f4-809c-46ac-ba03-f1df33a8737e%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/5935b1f4-809c-46ac-ba03-f1df33a8737e%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/5935b1f4-809c-46ac-ba03-f1df33a8737e%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAA0DmXZRMFsAMXCs9qmMk0KN%2B%2BuLh%3DCiEtP-r4vK3tZF0CRAmA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAA0DmXZRMFsAMXCs9qmMk0KN%2B%2BuLh%3DCiEtP-r4vK3tZF0CRAmA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:55am UTC](https://discuss.elastic.co/t/many-indices-fielddata-breaker-errors-in-logs-and-cluster-slow/20112/4 "2017-07-06T00:55:43Z")

</div>


