# \[parent\] data too large

**URL:** <https://discuss.elastic.co/t/parent-data-too-large/233671>\
**Category:** Elasticsearch\
**Created:** [May 21, 2020, 6:13am UTC](https://discuss.elastic.co/t/parent-data-too-large/233671 "2020-05-21T06:13:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ted\_ye](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@ted\_ye](https://discuss.elastic.co/u/ted_ye)\
**Post date:** [May 21, 2020, 6:13am UTC](https://discuss.elastic.co/t/parent-data-too-large/233671/1 "2020-05-21T06:13:33Z")

</div>

Hello , I am seeking the frequent occurence of the CircuitBreakingException in our ES cluster.  
org.elasticsearch.xpack.monitoring.exporter.ExportException: RemoteTransportException[[mdwdata04][10.10.30.66:9302][indices:data/write/bulk[s]]]; nested: CircuitBreakingException[[parent] Data too large, data for [\<transport\_request\>] would be [14685460692/13.6gb], which is larger than the limit of [14663286784/13.6gb], real usage: [14685456088/13.6gb], new bytes reserved: [4604/4.4kb], usages [request=0/0b, fielddata=48467/47.3kb, in\_flight\_requests=4604/4.4kb, accounting=98557832/93.9mb]];  
Caused by: org.elasticsearch.common.breaker.CircuitBreakingException: [parent] Data too large, data for [\<transport\_request\>] would be [14685460692/13.6gb], which is larger than the limit of [14663286784/13.6gb], real usage: [14685456088/13.6gb], new bytes reserved: [4604/4.4kb], usages [request=0/0b, fielddata=48467/47.3kb, in\_flight\_requests=4604/4.4kb, accounting=98557832/93.9mb

The ES version is 7.6.1  
ES cluster has three physical servers with 40 cores 126GB ram , each servers has one master node(with 4gb jvm) and one coordinate node(with 8gb jvm) and three data nodes (with 15gb jvm).  
My situation is writing logs into es with bulk request, and query with kibana. The query operations just use kibana's query with timestamp sort and aggregations, just like:  
{  
"version": true,  
"size": 500,  
"sort": [  
{  
"@timestamp": {  
"order": "desc",  
"unmapped\_type": "boolean"  
}  
}  
],  
"\_source": {  
"excludes":   
},  
"aggs": {  
"2": {  
"date\_histogram": {  
"field": "@timestamp",  
"fixed\_interval": "30s",  
"time\_zone": "Asia/Shanghai",  
"min\_doc\_count": 1  
}  
}  
},  
"stored\_fields": [  
"_"  
],  
"script\_fields": {},  
"docvalue\_fields": [  
{  
"field": "@timestamp",  
"format": "date\_time"  
}  
],  
"query": {  
"bool": {  
"must": [],  
"filter": [  
{  
"match\_all": {}  
},  
{  
"range": {  
"@timestamp": {  
"format": "strict\_date\_optional\_time",  
"gte": "2020-05-21T02:01:25.317Z",  
"lte": "2020-05-21T02:16:25.317Z"  
}  
}  
}  
],  
"should": [],  
"must\_not": []  
}  
},  
"highlight": {  
"pre\_tags": [  
"@kibana-highlighted-field@"  
],  
"post\_tags": [  
"@/kibana-highlighted-field@"  
],  
"fields": {  
"_": {}  
},  
"fragment\_size": 2147483647  
}  
}

I use GET /\_nodes/stats/breaker to observe each node and got the result like this:  
"parent" : {  
"limit\_size\_in\_bytes" : 14663286784,  
"limit\_size" : "13.6gb",  
"estimated\_size\_in\_bytes" : 11615692168,  
"estimated\_size" : "10.8gb",  
"overhead" : 1.0,  
"tripped" : 0  
}

So I want to know the root cause why the estimated\_size of parent brokers will rise and cause broker ,and how to avoid it.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2020, 6:13am UTC](https://discuss.elastic.co/t/parent-data-too-large/233671/2 "2020-06-18T06:13:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
