# Query shard exeption - all shards failed

**URL:** <https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494>\
**Category:** Elasticsearch\
**Created:** [July 4, 2018, 7:09am UTC](https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494 "2018-07-04T07:09:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [July 4, 2018, 7:09am UTC](https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494/1 "2018-07-04T07:09:09Z")

</div>

Hi, I'm encountering a problem while indexing some data. At the end of the post you can find the error message I can see from Logstash logs.  
It seems that Logstash (which is using a Elasticsearch filter plugin to enrich some data) can't complete the query because of an issue on Elasticsearch.  
If I query Elasticsearch from Kibana I get `Courier fetch: 1 of 2 shards failed.`

I tried to delete the index and re-index all data but the problem is always occurring.  
This is not the first time I use this Logstash instance to index some data with this filter, and the thing has always worked properly.

Could you please help me understanding what is going wrong?

Error message from Logstash:

`[2018-07-04T07:00:49,719][WARN][logstash.filters.elasticsearch] Failed to query elasticsearch for previous event {:index=>"logstash-zonabng", :query=>"bng_hostname:%{[bng_name]}", :event=>#<LogStash::Event:0x2f8b2082>, :error=>#<Elasticsearch::Transport::Transport::Errors::BadRequest: [400] {"error":{"root_cause":[{"type":"query_shard_exception","reason":"Failed to parse query [bng_hostname:%{[bng_name]}]","index_uuid":"xH492mfbTAiuFe_MGcWLSQ","index":"logstash-zonabng"}],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[{"shard":0,"index":"logstash-zonabng","node":"Q-diM7ALQqy8WYRA-hs5hg","reason":{"type":"query_shard_exception","reason":"Failed to parse query [bng_hostname:%{[bng_name]}]","index_uuid":"xH492mfbTAiuFe_MGcWLSQ","index":"logstash-zonabng","caused_by":{"type":"parse_exception","reason":"Cannot parse 'bng_hostname:%{[bng_name]}': Encountered \" \"]\" \"] \"\" at line 1, column 24.\nWas expecting:\n \"TO\" ...\n ","caused_by":{"type":"parse_exception","reason":"Encountered \" \"]\" \"] \"\" at line 1, column 24.\nWas expecting:\n \"TO\" ...\n "}}}}]},"status":400}>}`

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [July 4, 2018, 7:17am UTC](https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494/2 "2018-07-04T07:17:06Z")

</div>

> [@espogian](#):
>
> Failed to parse query [bng\_hostname:%{[bng\_name]}]"

as i know this error. see you data and filter or mapping.

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [July 4, 2018, 7:18am UTC](https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494/3 "2018-07-04T07:18:16Z")

</div>

The filter is correct since always worked with the data. From my understanding, the query is failing because a shard problem on Elasticsearch

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [July 4, 2018, 7:43am UTC](https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494/4 "2018-07-04T07:43:27Z")

</div>

This is the Logstash-Elasticsearch query filter. What happens to the document when the query fails? Should it be indexed in any case without the information retrieved from Elasticserach? Can this query be improved providing some sort of condition (if query fails then...)

```
    elasticsearch {
            hosts => ["elasticsearch:9200"]
            index => ["logstash-zonabng"]
            query => "bng_hostname:%{[bng_name]}"
            fields => {"zona_bng" => "zona_bng"}
    }
```

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [July 4, 2018, 7:53am UTC](https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494/5 "2018-07-04T07:53:55Z")

</div>

> [@espogian](#):
>
> query =\> "bng\_hostname:%{[bng\_name]}"

don't use this and try. use default query

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [July 4, 2018, 8:11am UTC](https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494/6 "2018-07-04T08:11:33Z")

</div>

The thing seems to be working now, but now I'm more interested to understand:

1. Why, if Logstash failed to query Elasticsearch I have a shard exeption from Kibana (should the two thing be uncorrelated?)
2. Which is the best practice to deal with these situation? I mean, I have an Elasticsearch query on Logstash that could fail sometimes. How can I avoid that this failure affects the whole shard?

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [July 5, 2018, 12:28am UTC](https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494/7 "2018-07-05T00:28:00Z")

</div>

> [@espogian](#):
>
> "bng\_hostname:%{[bng\_name]}"

this filed with data error, logstash can't display this.

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [July 7, 2018, 3:55pm UTC](https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494/8 "2018-07-07T15:55:59Z")

</div>

I would like to prevent Logstash to query Elasticsearch if \_elasticsearch\_lookup\_failure is in the tags, but apparently this thing is not working. I have tried to put a

if "\_elasticsearch\_lookup\_failure" not in [tags] {

in the filter plugin, but it is not doing the job

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2018, 3:56pm UTC](https://discuss.elastic.co/t/query-shard-exeption-all-shards-failed/138494/9 "2018-08-04T15:56:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
