# My 15m time filter searches hundreds of shards - why?

**URL:** <https://discuss.elastic.co/t/my-15m-time-filter-searches-hundreds-of-shards-why/125897>\
**Category:** Kibana\
**Created:** [March 28, 2018, 9:29am UTC](https://discuss.elastic.co/t/my-15m-time-filter-searches-hundreds-of-shards-why/125897 "2018-03-28T09:29:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmkgreen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jmkgreen/32/471_2.png) [@jmkgreen](https://discuss.elastic.co/u/jmkgreen)\
**Post date:** [March 28, 2018, 9:29am UTC](https://discuss.elastic.co/t/my-15m-time-filter-searches-hundreds-of-shards-why/125897/1 "2018-03-28T09:29:03Z")

</div>

I have a lot of daily indices, each with two shards. Yet a dashboard that predominantly searches two named indices (both of which are daily) tells me I'm search 350 shards (and some are failing to respond) with the last 15m selected.

My question is why? I can understand the queries involved being cast across a handful of shards but not 300+!

Is there any way I can debug what might be going on? This is with Elasticsearch 2.4 and Kibana 4.6.6.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 28, 2018, 10:09am UTC](https://discuss.elastic.co/t/my-15m-time-filter-searches-hundreds-of-shards-why/125897/2 "2018-03-28T10:09:44Z")

</div>

How is your index pattern defined?

---

<div class="post-metadata">

**Author:** ![jmkgreen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jmkgreen/32/471_2.png) [@jmkgreen](https://discuss.elastic.co/u/jmkgreen)\
**Post date:** [March 28, 2018, 10:54am UTC](https://discuss.elastic.co/t/my-15m-time-filter-searches-hundreds-of-shards-why/125897/3 "2018-03-28T10:54:44Z")

</div>

I've found the problem: the templates created each index with a static alias for the use of a separate application and some of the saved queries used by the dashboard were referencing this static alias.

I went into Kibana Objects and updated them. My dashboard now loads without shard failures being reported.

Of course, multi-month queries will still show the fault but at least that's a different problem.

---

<div class="post-metadata">

**Author:** ![jmkgreen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jmkgreen/32/471_2.png) [@jmkgreen](https://discuss.elastic.co/u/jmkgreen)\
**Post date:** [March 28, 2018, 10:57am UTC](https://discuss.elastic.co/t/my-15m-time-filter-searches-hundreds-of-shards-why/125897/4 "2018-03-28T10:57:30Z")

</div>

Incidentally the way to diagnose this (for others reading) was to use the web developer tools in the browser to find the request made of Kibana. The Request body has the query including the index names involved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2018, 10:57am UTC](https://discuss.elastic.co/t/my-15m-time-filter-searches-hundreds-of-shards-why/125897/5 "2018-04-25T10:57:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
