# Search\_phase\_execution\_exception filebeat all shards failed

**URL:** <https://discuss.elastic.co/t/search-phase-execution-exception-filebeat-all-shards-failed/259755>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 28, 2020, 6:56pm UTC](https://discuss.elastic.co/t/search-phase-execution-exception-filebeat-all-shards-failed/259755 "2020-12-28T18:56:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![whosecode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whosecode/32/81482_2.png) [@whosecode](https://discuss.elastic.co/u/whosecode)\
**Post date:** [December 28, 2020, 6:56pm UTC](https://discuss.elastic.co/t/search-phase-execution-exception-filebeat-all-shards-failed/259755/1 "2020-12-28T18:56:21Z")

</div>

Hi!

My ealstic cluster overview panel shows health yellow as shards are missing, and I get below reponses whenever I try to produce some visualization, or dashboard

```
search_phase_execution_exception
all shards failed

Error: Bad Request
at Fetch._callee3$ (http://localhost:5601/36063/bundles/core/core.entry.js:6:59535)
at l (http://localhost:5601/36063/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:380:1740520)
at Generator._invoke (http://localhost:5601/36063/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:380:1740273)
at Generator.forEach.e.<computed> [as next] (http://localhost:5601/36063/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:380:1740877)
at fetch_asyncGeneratorStep (http://localhost:5601/36063/bundles/core/core.entry.js:6:52652)
at _next (http://localhost:5601/36063/bundles/core/core.entry.js:6:52968)

```

I was able to look up the issue from the shards status url:  
[http://localhost:9200/\_cluster/health/?level=shards](http://localhost:9200/_cluster/health/?level=shards)

I was able to fix this by sending API request from Dev tools within kibana.

I used GET to display the settings for each indices, and found the filebeat has 1 no.of replicas configured (i guess by default), and I had to correct them to 0 because I have only single node running for the els.

```
GET _settings/

PUT filebeat-7.10.1/_settings
{
  "number_of_replicas": 0
}   

```

This is just an informational message, since I believe this might be useful for someone who got lost in this issue.

Thanks  
Shaheer

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [December 29, 2020, 1:11am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-filebeat-all-shards-failed/259755/2 "2020-12-29T01:11:42Z")

</div>

Hi @whosecode, welcome to the Elastic Community forums!

Thanks for reporting this issue. You can also set `setup.template.settings.index.number_of_replicas: 0` in your `filebeat.yml` before running Filebeat. Even better would be to set `setup.template.settings.index.auto_expand_replicas: "0-1"` so it adjusts according the number of data nodes in your Elasticsearch cluster.

Shaunak

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2021, 3:11am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-filebeat-all-shards-failed/259755/3 "2021-01-26T03:11:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
