# Nested aggregation query causing cluster failure

**URL:** <https://discuss.elastic.co/t/nested-aggregation-query-causing-cluster-failure/109595>\
**Category:** Elasticsearch\
**Created:** [November 29, 2017, 12:46pm UTC](https://discuss.elastic.co/t/nested-aggregation-query-causing-cluster-failure/109595 "2017-11-29T12:46:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AKwiro](https://avatars.discourse-cdn.com/v4/letter/a/b77776/32.png) [@AKwiro](https://discuss.elastic.co/u/AKwiro)\
**Post date:** [November 29, 2017, 12:46pm UTC](https://discuss.elastic.co/t/nested-aggregation-query-causing-cluster-failure/109595/1 "2017-11-29T12:46:07Z")

</div>

Hi all,

I am using elasticsearch 5.6.4 in a cluster setup.

Here's what my environment looks like:

- 5 nodes in the cluster.
- Each node has 16 GB of RAM and a VCPU with 4 cores.
- The setup is entirely hosted on the cloud.
- Cluster setup is the default setup, meaning every node performs all of the roles (data, ingest, master, etc.).

I have 4 indices on it. Each index is about 7 gigs with 5 shards and 1 replica dedicated to each.

Now the issue is when I try to run a nested aggregation query on it using python/console/curl, the entire cluster goes down. With the querying node going down first and then eventually all of them.

My query looks somewhat like this:

> ```
> GET indexname/_search
> {
> "aggs": {
> "first": {
> "terms": {
> "field": "Field1.keyword",
> "size": 100000
> },
> "aggs": {
> "second": {
> "terms": {
> "field": "Field2.keyword"
> },
> "aggs": {
> "third" {
> "terms": {
> "field": "Field3.keyword",
> }
> }
> }
> }
> }
> }
> }
> }
> 
> ```

Things that I have tried so far:

- Modify shard size.

- Experiment with heap size.

- Changing searching techniques (breadth first and depth first).

- Toggle execution hint.

- Modify timeout.

- Query using elasticsearch-dsl plugin for Python.

Any help is appreciated.

Thanks,  
AKwiro.

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [November 30, 2017, 4:17am UTC](https://discuss.elastic.co/t/nested-aggregation-query-causing-cluster-failure/109595/2 "2017-11-30T04:17:31Z")

</div>

I have ran into problems with Nested Aggregations in Elasticsearch. Is there a hard limit present in Elasticsearch that prevents one from performing deep aggregations?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2017, 4:17am UTC](https://discuss.elastic.co/t/nested-aggregation-query-causing-cluster-failure/109595/3 "2017-12-28T04:17:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
