# Search phase execution exception - Request to Elasticsearch failed

**URL:** <https://discuss.elastic.co/t/search-phase-execution-exception-request-to-elasticsearch-failed/216988>\
**Category:** Elasticsearch\
**Created:** [January 29, 2020, 11:25am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-request-to-elasticsearch-failed/216988 "2020-01-29T11:25:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Voula\_Mikr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/voula_mikr/32/58451_2.png) [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Post date:** [January 29, 2020, 11:25am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-request-to-elasticsearch-failed/216988/1 "2020-01-29T11:25:51Z")

</div>

Hi!

I am trying to add a sub-bucket in an kibana histogram and i get the bellow:

Request to Elasticsearch failed: {"error":{  
"root\_cause":

"type":"search\_phase\_execution\_exception","reason":"all shards failed","phase":"query","grouped":true,"failed\_shards":[

{"shard":0,"index":"data-20200123",  
"node":"CXFldNupTpObai1jt88wDg","reason":{"type":"too\_many\_buckets\_exception","reason":"Trying to create too many buckets. Must be less than or equal to:  
[10000] but was [10001]. This limit can be set by changing the [search.max\_buckets] cluster level setting.","max\_buckets":10000}},

{"shard":0,"index":"data-20200127",  
"node":"CXFldNupTpObai1jt88wDg","reason":{"type":"too\_many\_buckets\_exception","reason":"Trying to create too many buckets.  
Must be less than or equal to: [10000] but was [10001]. This limit can be set by changing the [search.max\_buckets] cluster level setting.","max\_buckets":10000}},

{"shard":0,"index":"data-a-20200123","node":"CXFldNupTpObai1jt88wDg","reason":{"type":"too\_many\_buckets\_exception","reason":"Trying to create too many buckets.  
Must be less than or equal to: [10000] but was [10001]. This limit can be set by changing the [search.max\_buckets] cluster level setting.","max\_buckets":10000}},

{"shard":0,"index":"data-20200127","node":"rF8XLfPSSkSUBUdIgr9Lzw","reason":{"type":"too\_many\_buckets\_exception","reason":"Trying to create too many buckets.  
Must be less than or equal to: [10000] but was [10001]. This limit can be set by changing the [search.max\_buckets] cluster level setting.","max\_buckets":10000}}  
]},

"status":503}

"search\_phase\_execution\_exception","reason":"all shards failed"

Since I have only 4 indices with total 200 docs and the distinguished values for the sub-bucket aggregation are 30 how it exceeds the max\_bucket (10000)?

Does the number of buckets has to do with all the sub-bucket aggregations cumulatively?

Is there any "formula" to calculate the buckets knowing the number of distinguished values of the sub-bucket aggregations (3 sub-buckets (terms) in a kibana histogram), the interval and the time period?  
For example:  
subbucket A : 30 distinguished values  
subbucket B: 5 distinguished values  
subbucket C: 10 distinguished values  
and all this requested 80 times in a time period.  
A multiplication of all these? (I guess that this way I will get the max possible but not the real number)

Or I have to count all the combinations from these 3 subbuckets I get for each moment in the time period and add all these numbers?  
For example:  
9:00 : results=8 (1 doc with aa-bb-cc / 4 docs with aa -bb -cb / 3 docs with ab -bb -cc)  
9:15 : results=9 (1 doc with aa-bb-cc / 4 docs with aa -bb -cb / 2 docs with ab -bb - cc / 2 docs with ab-bb-ca)  
9:30 : results=3 (1 doc with ad-bb-ca / 1 doc with aa -bb -cb / 1 docs with ab -bf -ca)

(Where e.g1 doc with ad-bb-ca means that the query for subbucket A has as result the value ad  
the query for subbucket B has as result the value bb  
and the query for subbucket C has as result the value ca  
)

So in this way the buckets for time period [9:00-9:30] will be 8+9+3 ?

Sorry for the long text!  
Thank you in advance!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2020, 11:25am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-request-to-elasticsearch-failed/216988/2 "2020-02-26T11:25:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
