# Max\_bucket and Kibana queries

**URL:** <https://discuss.elastic.co/t/max-bucket-and-kibana-queries/238407>\
**Category:** Elasticsearch\
**Created:** [June 24, 2020, 8:52am UTC](https://discuss.elastic.co/t/max-bucket-and-kibana-queries/238407 "2020-06-24T08:52:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Voula\_Mikr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/voula_mikr/32/58451_2.png) [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Post date:** [June 24, 2020, 8:52am UTC](https://discuss.elastic.co/t/max-bucket-and-kibana-queries/238407/1 "2020-06-24T08:52:10Z")

</div>

Hi,

I have about 30 indices in ElasticSearch with about 10.000.000 documents and they are under one index pattern of Kibana.  
One index of them ( data\_A ) , which has about 10.000 distinct values in the field " **c\_display\_name**", has 6.000.000 docs in Elasticsearch.  
I made a date histogram with the below request:

```
{
	"index": " **data***",
	"ignore_unavailable": true,
	"preference": 1592924167710
} {
	"aggs": {
		"2": {
			"date_histogram": {
				"field": "measurement_time",
				"interval": "3h",
				"time_zone": "Europe/Athens",
				"min_doc_count": 1
			},
			"aggs": {
				"3": {
					"terms": {
						"field": " **c_display_name**.keyword",
						**"size":** 10000,
						"order": {
							"_key": "asc"
						}
					},
					"aggs": {
						"1": {
							"avg": {
								"field": "c_value"
							}
						}
					}
				}
			}
		}
	},
	"size": 0,
	"_source": {
		"excludes": []
	},
	"stored_fields": ["*"],
	"script_fields": {},
	"docvalue_fields": [{
		"field": "date",
		"format": "date_time"
	}, {
		"field": "measurement_time",
		"format": "date_time"
	}],
	"query": {
		"bool": {
			"must": [{
				"range": {
					"measurement_time": {
						"format": "strict_date_optional_time",
						"gte": "2020-06-16T15:00:19.163Z",
						"lte": "2020-06-23T15:00:19.163Z"
					}
				}
			}],
			"filter": [{
				"match_all": {}
			}, {
				"match_all": {}
			}],
			"should": [],
			"must_not": []
		}
	},
	"timeout": "30000ms"
}

I also set **max_bucket to 350000** 
_cluster/settings
{
  "transient": {
    "search.max_buckets": 350000
  }
}
when I filter in order to see only the data_A I get 
FAILED TO LOAD RENSPONSE DATA .

By changing the size of c_display_name and max_bucket setting I see the below:

**c_display_name || max_bucket**
      10000 600000 -----> Client request timeout
      1000000 350000 -----> "too_many_buckets_exception"
      1000 350000 -----> get some buckets for data_A but also I get
                                                                                      a lot of "sum_other_doc_count": 259975
                                                                                                   "sum_other_doc_count": 260580, etc

```

How can I tune size of c\_display\_name, max\_buckets or timeout in order to see all the c\_display\_name values in the response of the histogram. Or what else should I do?

Thank you in advance.`Preformatted text`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2020, 8:52am UTC](https://discuss.elastic.co/t/max-bucket-and-kibana-queries/238407/2 "2020-07-22T08:52:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
