# Search Error - All Shards failed

**URL:** <https://discuss.elastic.co/t/search-error-all-shards-failed/263817>\
**Category:** Kibana\
**Created:** [February 10, 2021, 12:27am UTC](https://discuss.elastic.co/t/search-error-all-shards-failed/263817 "2021-02-10T00:27:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hyun\_Choi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hyun_choi/32/83182_2.png) [@Hyun\_Choi](https://discuss.elastic.co/u/Hyun_Choi)\
**Post date:** [February 10, 2021, 12:27am UTC](https://discuss.elastic.co/t/search-error-all-shards-failed/263817/1 "2021-02-10T00:27:35Z")

</div>

After parsing JSON log with the filter I used below

```
filter {
    if [type] == "vizql_cpp" or [type] == "vizql_tabprotosrv" {
        json {
            source => "message"
        }
        mutate {
            rename => { "v" => "v_%{k}" }
        }
        date {
            match => ["ts", "YYYY-MM-dd|HH:mm:ss", "MMM d HH:mm:ss", "MMM dd HH:mm:ss", "ISO8601"]
            target => "@timestamp"
        }
    }
}

```

I had to increase the "index.mapping.total\_fields.limit": 100000 as this JSON log file has created more than the default number of 1000 index fields and kept warning _**Limit of total fields [1000] has been exceeded**_

There were few warning regarding data type conversions like below.

_[2021-02-10T10:48:18,077][WARN][logstash.outputs.elasticsearch][main][5407fae34cad552531c896a58609701a37967d1fe753424bc18f596bd9c3372e] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"06543072-vizql\_cpp2", :routing=\>nil, :\_type=\>"\_doc"}, #LogStash::Event:0x3db19409], :response=\>{"index"=\>{"\_index"=\>"06543072-vizql\_cpp2", "\_type"=\>"\_doc", "\_id"=\>"b40yiXcBtCBrnwvsEjrn", "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"mapper [v\_server-startup-options.file.encoding] cannot be changed from type [text] to [ObjectMapper]"}}}}_

Ignoring the warning above, the index created and the final result of index pattern in Kibana was 9055 fields in total.

 ![2021-02-10_9-14-18](https://us1.discourse-cdn.com/elastic/original/3X/3/4/3478f91e216a86dc4fd27f7ea9d61cfab6af4f81.png)

With that index, search keyword 'error' given, throw an search error regardless Lucene or KQL. The error saying 'all shards failed'

 ![2021-02-10_8-58-19](https://us1.discourse-cdn.com/elastic/original/3X/7/3/7374eb4d896a89678f3809cf46e5d3b0cf9d57c3.png)  
 ![2021-02-10_8-56-12](https://us1.discourse-cdn.com/elastic/original/3X/6/2/6240d9aeb138a737de76f69d45703f540ec26be1.png)

I have a single node Elasticsearch.  
The health of the index in the summary page is green with the settings as below.

 ![2021-02-10_11-31-50](https://us1.discourse-cdn.com/elastic/original/3X/2/2/22433e76cb5f1c0346d7037c663634f23c302ef9.png)  
{  
"index.blocks.read\_only\_allow\_delete": "false",  
"index.priority": "1",  
"index.query.default\_field": [  
"\*"  
],  
"index.refresh\_interval": "1s",  
"index.write.wait\_for\_active\_shards": "1",  
"index.routing.allocation.include.\_tier\_preference": "data\_content",  
"index.mapping.total\_fields.limit": "100000",  
"index.mapping.ignore\_malformed": "true",  
"index.number\_of\_replicas": "0"  
}

**What went wrong? Any idea?**

The Json log file looks like as below.  
{"ts":"2020-12-12T00:00:12.305","pid":6648,"tid":"5578","sev":"info","req":"-","sess":"-","site":"-","user":"-","k":"rotate-log","v":{"new-path":"C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\nativeapi\_vizqlserver\_1-0\_2020\_12\_12\_00\_00\_00.txt","old-path":"C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\nativeapi\_vizqlserver\_1-0\_2020\_12\_11\_00\_00\_00.txt"}}  
{"ts":"2020-12-12T00:00:12.303","pid":6648,"tid":"52b0","sev":"info","req":"-","sess":"-","site":"-","user":"-","k":"msg","v":"Resource Manager: CPU info: 0%"}  
{"ts":"2020-12-12T00:00:12.303","pid":6648,"tid":"52b0","sev":"info","req":"-","sess":"-","site":"-","user":"-","k":"msg","v":"Resource Manager: Memory info: 1,801,904,128 bytes (current process);14,939,303,936 bytes (Tableau total); 29,661,540,352 bytes (total of all processes); 11 (info count)"}  
{"ts":"2020-12-12T00:00:12.304","pid":6648,"tid":"52b0","sev":"info","req":"-","sess":"-","site":"-","user":"-","k":"cachingdomparser-getdom-stats","v":{"elements-count":4,"hits":0,"logging-period-in-sec":60,"misses":0}}  
{"ts":"2020-12-12T00:01:12.313","pid":6648,"tid":"52b0","sev":"info","req":"-","sess":"-","site":"-","user":"-","k":"msg","v":"Resource Manager: CPU info: 0%"}

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [February 10, 2021, 8:28am UTC](https://discuss.elastic.co/t/search-error-all-shards-failed/263817/2 "2021-02-10T08:28:22Z")

</div>

Hi and welcome to our community!

I'd need some additional information about this, so what version of the Elastic stack are you using? Could you record and share a HAR file, when you experience the error in Discover? There should be errors in you Elasticsearch log file, could you share them?

Many thx and best,  
Matthias

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2021, 8:29am UTC](https://discuss.elastic.co/t/search-error-all-shards-failed/263817/3 "2021-03-10T08:29:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
