# Search parse exceptions on marvel dashboard

**URL:** <https://discuss.elastic.co/t/search-parse-exceptions-on-marvel-dashboard/17871>\
**Category:** Elasticsearch\
**Created:** [June 3, 2014, 4:43am UTC](https://discuss.elastic.co/t/search-parse-exceptions-on-marvel-dashboard/17871 "2014-06-03T04:43:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhil\_Mulley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_mulley/32/1401_2.png) [@Nikhil\_Mulley](https://discuss.elastic.co/u/Nikhil_Mulley)\
**Post date:** [June 3, 2014, 4:43am UTC](https://discuss.elastic.co/t/search-parse-exceptions-on-marvel-dashboard/17871/1 "2014-06-03T04:43:13Z")

</div>

Hi,

In my elasticsearch cluster, off late on the marvel dashboard there are  
searchparseexceptions. Any idea what are these below exceptions mean? They  
seem to be happening very recently and even restart of the elasticsearch  
service does not seem to help.

Environment: ElasticSearch 0.90 + LogStash 1.2.1. Java 1.7.0\_40

SearchParseException[[.marvel-2014.06.03][0]: from[-1],size[-1]: Parse  
Failure [Failed to parse source  
[{"facets":{"0":{"date\_histogram":{"key\_field":"@timestamp","value\_field":"primaries.indexing.index\_total","interval":"1m"},"global":true,"facet\_filter":{"fquery":{"query":{"filtered":{"query":{"query\_string":{"query":"\_type:indices\_stats"}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"from":1401766706046,"to":"now"}}}]}}}}}}}},"size":50,"query":{"filtered":{"query":{"query\_string":{"query":"\_type:cluster\_event  
OR  
\_type:node\_event"}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"from":1401766706046,"to":"now"}}}]}}}},"sort":[{"@timestamp":{"order":"desc"}},{"@timestamp":{"order":"desc"}}]}]]]

What is the source that is leading the queries problematic? Is it the index  
being corrupt and not useful? Any insight will be helpful.

Thanks,  
Nikhil

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b809a823-4204-4b13-b832-13ae12be2ed2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b809a823-4204-4b13-b832-13ae12be2ed2%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Boaz\_Leskes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/boaz_leskes/32/723_2.png) [@Boaz\_Leskes](https://discuss.elastic.co/u/Boaz_Leskes)\
**Post date:** [June 3, 2014, 6:44am UTC](https://discuss.elastic.co/t/search-parse-exceptions-on-marvel-dashboard/17871/2 "2014-06-03T06:44:47Z")

</div>

Hi Nikhil,

Your ES logs will indicate which field was exactly missing, but I suspect  
you didn't install Marvel on all your nodes, typically this happens when  
the master nodes is missing it. Can this be?

Cheers,  
Boaz

On Tuesday, June 3, 2014 6:43:13 AM UTC+2, Nikhil Mulley wrote:

> Hi,
> 
> In my elasticsearch cluster, off late on the marvel dashboard there are  
> searchparseexceptions. Any idea what are these below exceptions mean? They  
> seem to be happening very recently and even restart of the elasticsearch  
> service does not seem to help.
> 
> Environment: Elasticsearch 0.90 + LogStash 1.2.1. Java 1.7.0\_40
> 
> SearchParseException[[.marvel-2014.06.03][0]: from[-1],size[-1]: Parse  
> Failure [Failed to parse source  
> [{"facets":{"0":{"date\_histogram":{"key\_field":"@timestamp","value\_field":"primaries.indexing.index\_total","interval":"1m"},"global":true,"facet\_filter":{"fquery":{"query":{"filtered":{"query":{"query\_string":{"query":"\_type:indices\_stats"}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"from":1401766706046,"to":"now"}}}]}}}}}}}},"size":50,"query":{"filtered":{"query":{"query\_string":{"query":"\_type:cluster\_event  
> OR  
> \_type:node\_event"}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"from":1401766706046,"to":"now"}}}]}}}},"sort":[{"@timestamp":{"order":"desc"}},{"@timestamp":{"order":"desc"}}]}]]]
> 
> What is the source that is leading the queries problematic? Is it the  
> index being corrupt and not useful? Any insight will be helpful.
> 
> Thanks,  
> Nikhil

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/8b31667a-6b78-465a-8a0a-e1b7503d521c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/8b31667a-6b78-465a-8a0a-e1b7503d521c%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Nikhil\_Mulley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_mulley/32/1401_2.png) [@Nikhil\_Mulley](https://discuss.elastic.co/u/Nikhil_Mulley)\
**Post date:** [June 4, 2014, 5:36am UTC](https://discuss.elastic.co/t/search-parse-exceptions-on-marvel-dashboard/17871/3 "2014-06-04T05:36:11Z")

</div>

Thanks for the reply Boaz.

Marvel has been installed as a plugin on all the 4 nodes that I have as  
part of the cluster. Do not see anything specific in ES logs although I see  
plenty of exceptions related to netty, which I am not sure are if anyway  
related to the search parse exceptions on the marvel dashboard.

On Monday, June 2, 2014 11:44:47 PM UTC-7, Boaz Leskes wrote:

> Hi Nikhil,
> 
> Your ES logs will indicate which field was exactly missing, but I suspect  
> you didn't install Marvel on all your nodes, typically this happens when  
> the master nodes is missing it. Can this be?
> 
> Cheers,  
> Boaz
> 
> On Tuesday, June 3, 2014 6:43:13 AM UTC+2, Nikhil Mulley wrote:
> 
> > Hi,
> > 
> > In my elasticsearch cluster, off late on the marvel dashboard there are  
> > searchparseexceptions. Any idea what are these below exceptions mean? They  
> > seem to be happening very recently and even restart of the elasticsearch  
> > service does not seem to help.
> > 
> > Environment: Elasticsearch 0.90 + LogStash 1.2.1. Java 1.7.0\_40
> > 
> > SearchParseException[[.marvel-2014.06.03][0]: from[-1],size[-1]: Parse  
> > Failure [Failed to parse source  
> > [{"facets":{"0":{"date\_histogram":{"key\_field":"@timestamp","value\_field":"primaries.indexing.index\_total","interval":"1m"},"global":true,"facet\_filter":{"fquery":{"query":{"filtered":{"query":{"query\_string":{"query":"\_type:indices\_stats"}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"from":1401766706046,"to":"now"}}}]}}}}}}}},"size":50,"query":{"filtered":{"query":{"query\_string":{"query":"\_type:cluster\_event  
> > OR  
> > \_type:node\_event"}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"from":1401766706046,"to":"now"}}}]}}}},"sort":[{"@timestamp":{"order":"desc"}},{"@timestamp":{"order":"desc"}}]}]]]
> > 
> > What is the source that is leading the queries problematic? Is it the  
> > index being corrupt and not useful? Any insight will be helpful.
> > 
> > Thanks,  
> > Nikhil

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4c648be3-739c-46be-8716-064b866d5fad%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4c648be3-739c-46be-8716-064b866d5fad%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Nikhil\_Mulley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_mulley/32/1401_2.png) [@Nikhil\_Mulley](https://discuss.elastic.co/u/Nikhil_Mulley)\
**Post date:** [June 4, 2014, 6:07am UTC](https://discuss.elastic.co/t/search-parse-exceptions-on-marvel-dashboard/17871/4 "2014-06-04T06:07:32Z")

</div>

It turns out that I had to delete the older indices on elasticsearch  
cluster lying around for a very long period of time. After cleaning up some  
and restarting the cluster, exceptions in elasticsearch logs have come down  
and marvel dashboard is also neat showing the cluster status to be green.  
Thanks.

On Tuesday, June 3, 2014 10:36:11 PM UTC-7, Nikhil Mulley wrote:

> Thanks for the reply Boaz.
> 
> Marvel has been installed as a plugin on all the 4 nodes that I have as  
> part of the cluster. Do not see anything specific in ES logs although I see  
> plenty of exceptions related to netty, which I am not sure are if anyway  
> related to the search parse exceptions on the marvel dashboard.
> 
> On Monday, June 2, 2014 11:44:47 PM UTC-7, Boaz Leskes wrote:
> 
> > Hi Nikhil,
> > 
> > Your ES logs will indicate which field was exactly missing, but I suspect  
> > you didn't install Marvel on all your nodes, typically this happens when  
> > the master nodes is missing it. Can this be?
> > 
> > Cheers,  
> > Boaz
> > 
> > On Tuesday, June 3, 2014 6:43:13 AM UTC+2, Nikhil Mulley wrote:
> > 
> > > Hi,
> > > 
> > > In my elasticsearch cluster, off late on the marvel dashboard there are  
> > > searchparseexceptions. Any idea what are these below exceptions mean? They  
> > > seem to be happening very recently and even restart of the elasticsearch  
> > > service does not seem to help.
> > > 
> > > Environment: Elasticsearch 0.90 + LogStash 1.2.1. Java 1.7.0\_40
> > > 
> > > SearchParseException[[.marvel-2014.06.03][0]: from[-1],size[-1]: Parse  
> > > Failure [Failed to parse source  
> > > [{"facets":{"0":{"date\_histogram":{"key\_field":"@timestamp","value\_field":"primaries.indexing.index\_total","interval":"1m"},"global":true,"facet\_filter":{"fquery":{"query":{"filtered":{"query":{"query\_string":{"query":"\_type:indices\_stats"}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"from":1401766706046,"to":"now"}}}]}}}}}}}},"size":50,"query":{"filtered":{"query":{"query\_string":{"query":"\_type:cluster\_event  
> > > OR  
> > > \_type:node\_event"}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"from":1401766706046,"to":"now"}}}]}}}},"sort":[{"@timestamp":{"order":"desc"}},{"@timestamp":{"order":"desc"}}]}]]]
> > > 
> > > What is the source that is leading the queries problematic? Is it the  
> > > index being corrupt and not useful? Any insight will be helpful.
> > > 
> > > Thanks,  
> > > Nikhil

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3b408d05-acf3-4422-bf90-c9c69395c86b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3b408d05-acf3-4422-bf90-c9c69395c86b%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:24am UTC](https://discuss.elastic.co/t/search-parse-exceptions-on-marvel-dashboard/17871/5 "2017-07-06T01:24:47Z")

</div>


