# SearchParseException\[failed to parse search source \[\_na\_\]\];

**URL:** <https://discuss.elastic.co/t/searchparseexception-failed-to-parse-search-source--na-/56596>\
**Category:** Elasticsearch\
**Created:** [July 28, 2016, 9:20am UTC](https://discuss.elastic.co/t/searchparseexception-failed-to-parse-search-source--na-/56596 "2016-07-28T09:20:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![usego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usego/32/11096_2.png) [@usego](https://discuss.elastic.co/u/usego)\
**Post date:** [July 28, 2016, 9:20am UTC](https://discuss.elastic.co/t/searchparseexception-failed-to-parse-search-source--na-/56596/1 "2016-07-28T09:20:17Z")

</div>

Could you point please me in the right direction. I have a small cluster with 2 nodes [MX203][10.40.0.203:9300] and [MX105][10.40.0.105:9300] . Periodically logs are overwhelmed with tons of messages like

`[2016-07-28 12:08:48,220][DEBUG][action.search] [MX203] [indexname][0], node[MqfyLJodStKEdgTyaIVbiw], [R], v[31], s [STARTED], a[id=DUDfV75ETbmtOjzsbijXiA]: Failed to execute [org.elasticsearch.action.search.SearchRequest@57d98094] lastShard [true] RemoteTransportException[[MX105][10.40.0.105:9300][indices:data/read/search[phase/query]]]; nested: SearchParseException[failed to parse search source [_na_]]; nested: ElasticsearchParseException[Failed to derive xcontent]; Caused by: SearchParseException[failed to parse search source [_na_]]; nested: ElasticsearchParseException[Failed to derive xcontent]; at org.elasticsearch.search.SearchService.parseSource(SearchService.java:855) at org.elasticsearch.search.SearchService.createContext(SearchService.java:654) at org.elasticsearch.search.SearchService.createAndPutContext(SearchService.java:620) at org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:371) at org.elasticsearch.search.action.SearchServiceTransportAction$SearchQueryTransportHandler.messageReceived(SearchServiceTransportAction.java: 368) at org.elasticsearch.search.action.SearchServiceTransportAction$SearchQueryTransportHandler.messageReceived(SearchServiceTransportAction.java: 365) at org.elasticsearch.transport.TransportRequestHandler.messageReceived(TransportRequestHandler.java:33) at org.elasticsearch.transport.RequestHandlerRegistry.processMessageReceived(RequestHandlerRegistry.java:75) at org.elasticsearch.transport.netty.MessageChannelHandler$RequestHandler.doRun(MessageChannelHandler.java:300) at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615) at java.lang.Thread.run(Thread.java:745) Caused by: ElasticsearchParseException[Failed to derive xcontent] at org.elasticsearch.common.xcontent.XContentFactory.xContent(XContentFactory.java:240) at org.elasticsearch.search.SearchService.parseSource(SearchService.java:824) ... 12 more`

where [indexname] is any of existing indexes even not participating in search.

I'm confused with :9300, so it look like replication? But this is definitely connected to queries as if queries are stopped, exceptions do not appear in log anymore.

Cluster is green.  
Elasticsearch 2.3.4 on Ubuntu

---

<div class="post-metadata">

**Author:** ![javanna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javanna/32/4698_2.png) [@javanna](https://discuss.elastic.co/u/javanna)\
**Post date:** [July 28, 2016, 10:48am UTC](https://discuss.elastic.co/t/searchparseexception-failed-to-parse-search-source--na-/56596/2 "2016-07-28T10:48:48Z")

</div>

That's a query that cannot be parsed on index `indexname`, shard `0`.

Maybe some malformed query ends up being executed against that index? The log you see contains an error received from another node. The nodes communication through the transport layer, and that is why you see the 9300 port in there.

I'd suggest to verify which queries get sent to the cluster, and double check whether you get back any error. Also, do check the `_shards` header that the search api returns. That section contains how many shards successfully executed the query, and how many failed. It can happen that you get a 200 - OK response although some shards failed.

---

<div class="post-metadata">

**Author:** ![usego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usego/32/11096_2.png) [@usego](https://discuss.elastic.co/u/usego)\
**Post date:** [July 29, 2016, 9:14am UTC](https://discuss.elastic.co/t/searchparseexception-failed-to-parse-search-source--na-/56596/3 "2016-07-29T09:14:40Z")

</div>

Thanks. I'm understanding better how things work now .

We found one bad written query raising those errors.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:31pm UTC](https://discuss.elastic.co/t/searchparseexception-failed-to-parse-search-source--na-/56596/4 "2017-07-05T22:31:51Z")

</div>


