# Max\_bucket exception from elasticsearch

**URL:** <https://discuss.elastic.co/t/max-bucket-exception-from-elasticsearch/237732>\
**Category:** Elasticsearch\
**Created:** [June 19, 2020, 5:57am UTC](https://discuss.elastic.co/t/max-bucket-exception-from-elasticsearch/237732 "2020-06-19T05:57:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Voula\_Mikr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/voula_mikr/32/58451_2.png) [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Post date:** [June 19, 2020, 5:57am UTC](https://discuss.elastic.co/t/max-bucket-exception-from-elasticsearch/237732/1 "2020-06-19T05:57:37Z")

</div>

Hi,

I have made a control visualization (option list) with 4 options-fields (let's say A, B, C & D).  
The "size" field of each option is 10000 and search.max\_buckets setting is 10000 too.

In ElasticSearch, for field A there are 2 distinguished values , A1 & A2.  
The documents with **A1 value in A field are 14800000** and they have **1028 distinguished values** in field **B**.  
The documents with **A2 value in A field are 3700000** and they have **3500 distinguished values** in field **B**.

In control visualization, when I select for field A the A1 value I get the error "5 of 12 shards failed" and when I inspect the query and the response to elasticsearch I see that

"type": "too\_many\_buckets\_exception",  
"reason": "Trying to create too many buckets. Must be less than or equal to: [10000] but was [10001]. This limit can be set by changing the [search.max\_buckets] cluster level setting.",

But when I select A2 everything is ok.

Why the error is not shown with value A2?  
Is this because, with a simple calculation, the unique buckets for A1 value are14800000 : 1028 = 14396,.... and greater than max\_bucket or "size"  
and for A2 are 3700000 : 3500 = 1057,.... ??

Also, I saw that \* _max\_buckets = size 1.5 + 10_ in [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#\_shard\_size\_3](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_shard_size_3)  
That means that "size" should be set max to 6660 if max\_bucket = 10000 ?  
If I set size to 6000 there is no problem but if I set to 7000 I see againe the too\_many\_buckets\_exception for A1.

Which value , max\_bucket or "size" should I change in order not to get exceptions? Which calculations should I do?

Thank you in advance!

BR  
Paraskevi

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [June 19, 2020, 7:50am UTC](https://discuss.elastic.co/t/max-bucket-exception-from-elasticsearch/237732/2 "2020-06-19T07:50:41Z")

</div>

How long the time range that you want to display?  
If the time range too wide, you need to increase the minimum interval of the bucket.  
The higher minimum interval, the smallest bucket that you need.  
If you need the minimum interval as you want and hit the max\_bucket, you can increase the max\_bucket using:

```auto
PUT _cluster/settings { "persistent": { "search.max_buckets": 20000 } } 

```

---

<div class="post-metadata">

**Author:** ![Voula\_Mikr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/voula_mikr/32/58451_2.png) [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Post date:** [June 19, 2020, 8:06am UTC](https://discuss.elastic.co/t/max-bucket-exception-from-elasticsearch/237732/3 "2020-06-19T08:06:53Z")

</div>

Hi Fadjar,

Thanks for the prompt answer. My concern basically is to understand how the number of buckets is calculated. I don't want to change the interval, I know the unique values of some fields so I would like to calculate the "possible" max\_buckets number and not to increase to an "enough big" number because in that case I don't know if , for example, a change like this will increase cpu etc.  
Could you please explain based on the example given above?

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [June 19, 2020, 8:20am UTC](https://discuss.elastic.co/t/max-bucket-exception-from-elasticsearch/237732/4 "2020-06-19T08:20:00Z")

</div>

If you're using datetime histogram and don;t want to change the cluster setting, just reduce the time range of the dashboard.  
The search.max\_bucket id using the minimum interval in the time range of the query that you used.  
Wider time range with smaller minimum interval, makes the bucket grow.  
In my experienced, this max\_bucket problem will occurred if I have long range of time query....  
Another solution as I've done, using transforms.

Regards,  
Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2020, 8:20am UTC](https://discuss.elastic.co/t/max-bucket-exception-from-elasticsearch/237732/5 "2020-07-17T08:20:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
