# Shards fail in high amount on certain Index

**URL:** <https://discuss.elastic.co/t/shards-fail-in-high-amount-on-certain-index/214030>\
**Category:** Kibana\
**Created:** [January 7, 2020, 10:55am UTC](https://discuss.elastic.co/t/shards-fail-in-high-amount-on-certain-index/214030 "2020-01-07T10:55:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Moritz\_Kiesewetter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moritz_kiesewetter/32/51243_2.png) [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Post date:** [January 7, 2020, 10:55am UTC](https://discuss.elastic.co/t/shards-fail-in-high-amount-on-certain-index/214030/1 "2020-01-07T10:55:23Z")

</div>

Hi guys,

when i take a look at one of my dashboards, which uses the Auditbeat-Index as an Input, i get an "20/24 Shards failed" Error like 20 Times on the side of my screen. It's stated as an illegal\_arguement\_expression with the following Message:

> Type  
> illegal\_argument\_exception  
> Reason  
> Fielddata is disabled on text fields by default. Set fielddata=true on [user.name] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead.

So i don't really know what exactly i'm supposed to do here, and where to do it. Any hellp will be appreciated.

Cheers,  
Mo

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [January 8, 2020, 4:29pm UTC](https://discuss.elastic.co/t/shards-fail-in-high-amount-on-certain-index/214030/2 "2020-01-08T16:29:08Z")

</div>

Hi, it looks like your Auditbeat index has data where `user.name` is mapped as a `text` field. I am guessing it should be mapped as a keyword (as the error messages says) so that you can make aggregate searches on that field.

It could mean there is a mapping conflict in Elasticsearch, or the mapping template for the Auditbeat index was accidentally deleted. You'll need to restore the mappings so that new Auditbeat indices have the data mapped correctly, but also reindex the existing data so the `user.name` fields are re-mapped as keyword.

---

<div class="post-metadata">

**Author:** ![Moritz\_Kiesewetter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moritz_kiesewetter/32/51243_2.png) [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Post date:** [January 10, 2020, 6:42am UTC](https://discuss.elastic.co/t/shards-fail-in-high-amount-on-certain-index/214030/3 "2020-01-10T06:42:03Z")

</div>

Ok, thanks tsullivan, will try today.  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2020, 6:56am UTC](https://discuss.elastic.co/t/shards-fail-in-high-amount-on-certain-index/214030/4 "2020-02-07T06:56:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
