# Oops! SearchPhaseExecutionException\[Failed to execute phase \[query\], all shards failed\]

**URL:** <https://discuss.elastic.co/t/oops-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/21565>\
**Category:** Elasticsearch\
**Created:** [January 9, 2015, 8:58pm UTC](https://discuss.elastic.co/t/oops-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/21565 "2015-01-09T20:58:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Taylor\_Wood](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@Taylor\_Wood](https://discuss.elastic.co/u/Taylor_Wood)\
**Post date:** [January 9, 2015, 8:58pm UTC](https://discuss.elastic.co/t/oops-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/21565/1 "2015-01-09T20:58:07Z")

</div>

History: I have been testing ELK stack for a few months now off and on.  
For months now I have had it logging correctly with no major issues. I  
picked this back up this week and everything was logging perfectly with 1  
exception: I am logging to the main partition and not the /data partition  
we setup. After logging a very large log file we began to get alerts that  
our disk was getting full. Today I was making a change to the  
elasticsearch.yml to have logs be stored on the /data partition and now no  
dashboards are visible in Kibana. Instead I get the following "! SearchPhaseExecutionException[Failed  
to execute phase [query], all shards failed]"

I have reverted to how it was setup previously and logging to the main  
partition which is not full:  
Filesystem Size Used Avail Use% Mounted on  
/dev/vda1 24G 16G 6.4G 72% /

Looking at other posts This seems to be the starting point but I am at a  
loss on where to turn now:  
[elasticsearch]# curl -XGET  
'[http://localhost:9200/\_cluster/health?pretty=true](http://localhost:9200/_cluster/health?pretty=true)'  
{  
"cluster\_name" : "elasticsearch",  
"status" : "red",  
"timed\_out" : false,  
"number\_of\_nodes" : 2,  
"number\_of\_data\_nodes" : 1,  
"active\_primary\_shards" : 575,  
"active\_shards" : 575,  
"relocating\_shards" : 0,  
"initializing\_shards" : 0,  
"unassigned\_shards" : 585  
}

I can not seem to grasp the concept of the shards, why they are now  
unassigned, or why our elasticsearch no longer works correctly.

Any help is greatly appreciated.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/31caefbe-1cc2-4d9c-a309-f03036e1dda6%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/31caefbe-1cc2-4d9c-a309-f03036e1dda6%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Taylor\_Wood](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@Taylor\_Wood](https://discuss.elastic.co/u/Taylor_Wood)\
**Post date:** [January 12, 2015, 4:27pm UTC](https://discuss.elastic.co/t/oops-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/21565/2 "2015-01-12T16:27:50Z")

</div>

> Today the Kibana interface appears to be working fine but the status is
> 
> > still red.
> 
> > [root@syslog1 ~]# curl -XGET  
> > '[http://localhost:9200/\_cluster/health?pretty=true](http://localhost:9200/_cluster/health?pretty=true)'  
> > {  
> > "cluster\_name" : "elasticsearch",  
> > "status" : "red",  
> > "timed\_out" : false,  
> > "number\_of\_nodes" : 2,  
> > "number\_of\_data\_nodes" : 1,  
> > "active\_primary\_shards" : 590,  
> > "active\_shards" : 590,  
> > "relocating\_shards" : 0,  
> > "initializing\_shards" : 0,  
> > "unassigned\_shards" : 600  
> > }  
> > [root

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/1afb3e14-f845-4772-9520-08d65bd5dede%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1afb3e14-f845-4772-9520-08d65bd5dede%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Taylor\_Wood](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@Taylor\_Wood](https://discuss.elastic.co/u/Taylor_Wood)\
**Post date:** [March 12, 2015, 5:35pm UTC](https://discuss.elastic.co/t/oops-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/21565/3 "2015-03-12T17:35:12Z")

</div>

I didn't get any help on this but as an FYI for those that may have this  
issue and are just starting:

Digging deeper it appears our system was created with 5 shards and 1  
replica. Granted we are only using 1 node so every day elasticsearch  
would create an indice of 10 shards, 5 for the primary node and 5 for the  
secondary node (which doesn't exist on our system but would for  
redundancy). We made it so all future indices created have 0 replicas in  
the future. I can't find a way to clean up all the unallocated shards  
from previous indices without deleting the data.

If the active shards is almost = to unassigned shards you are using  
replication and need to have a second node running.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a0c368f4-2550-459b-b61e-6f781477eaee%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a0c368f4-2550-459b-b61e-6f781477eaee%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Aaron\_Mefford](https://avatars.discourse-cdn.com/v4/letter/a/f0a364/32.png) [@Aaron\_Mefford](https://discuss.elastic.co/u/Aaron_Mefford)\
**Post date:** [March 13, 2015, 1:06am UTC](https://discuss.elastic.co/t/oops-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/21565/4 "2015-03-13T01:06:07Z")

</div>

You should be able to set the number of replicas for all previous indexes  
to 0. You cannot reduce the shard count once an index is created, or  
increase for that matter. You could reindex your shards.

> **[Update index settings API | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-update-settings.html)**

curl -XPUT 'localhost:9200/my\_index/\_settings' -d '  
{  
"index" : {  
"number\_of\_replicas" : 0  
}  
}'

On Thursday, March 12, 2015 at 11:35:12 AM UTC-6, Taylor Wood wrote:

> I didn't get any help on this but as an FYI for those that may have this  
> issue and are just starting:
> 
> Digging deeper it appears our system was created with 5 shards and 1  
> replica. Granted we are only using 1 node so every day elasticsearch  
> would create an indice of 10 shards, 5 for the primary node and 5 for the  
> secondary node (which doesn't exist on our system but would for  
> redundancy). We made it so all future indices created have 0 replicas in  
> the future. I can't find a way to clean up all the unallocated shards  
> from previous indices without deleting the data.
> 
> If the active shards is almost = to unassigned shards you are using  
> replication and need to have a second node running.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0b36108c-3e90-4865-85e3-d6a74b53ee97%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0b36108c-3e90-4865-85e3-d6a74b53ee97%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Taylor\_Wood](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@Taylor\_Wood](https://discuss.elastic.co/u/Taylor_Wood)\
**Post date:** [March 13, 2015, 5:57pm UTC](https://discuss.elastic.co/t/oops-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/21565/5 "2015-03-13T17:57:58Z")

</div>

The following as suggested was able to fix all my previous indexes to make  
0 replication and essentially removing the 5 unassigned shards we had per  
Indice.

curl -XPUT 'localhost:9200/\*/\_settings' -d ' { "index" : {  
"number\_of\_replicas" : 0 } } '

Thank you.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/f4c18070-a29d-429d-87fb-c358d175e938%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f4c18070-a29d-429d-87fb-c358d175e938%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:26am UTC](https://discuss.elastic.co/t/oops-searchphaseexecutionexception-failed-to-execute-phase-query-all-shards-failed/21565/6 "2017-07-06T00:26:55Z")

</div>


