# Shards failed in kibana

**URL:** <https://discuss.elastic.co/t/shards-failed-in-kibana/310559>\
**Category:** Elasticsearch\
**Created:** [July 25, 2022, 4:17pm UTC](https://discuss.elastic.co/t/shards-failed-in-kibana/310559 "2022-07-25T16:17:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![OoO](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ooo/32/103296_2.png) [@OoO](https://discuss.elastic.co/u/OoO)\
**Post date:** [July 25, 2022, 4:17pm UTC](https://discuss.elastic.co/t/shards-failed-in-kibana/310559/1 "2022-07-25T16:17:48Z")

</div>

Hello world,  
Since I upgraded filebeat from 7.x to 8.x ( the version of my ELK and filebeat is 8.2.3 now), I can't see the dashboard anymore, I have encountered this problem on kibana:

> 1 of 8 shards failed  
> The data you are seeing might be incomplete or wrong.

and the information complet is:

> Type illegal\_argument\_exception  
> Reason  
> Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [host.name] in order to load field data by uninverting the inverted index. Note that this can use significant memory.

It seems like my index partterns can't refresh itself, I would like to ask if the only way to solve it is to manually add all the miss field?  
(I hope not 🙂 )

Best regard

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 26, 2022, 12:09am UTC](https://discuss.elastic.co/t/shards-failed-in-kibana/310559/2 "2022-07-26T00:09:38Z")

</div>

When you upgraded Filebeat did you re-run the setup command to upgrade the dashboards?

---

<div class="post-metadata">

**Author:** ![OoO](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ooo/32/103296_2.png) [@OoO](https://discuss.elastic.co/u/OoO)\
**Post date:** [July 26, 2022, 9:26am UTC](https://discuss.elastic.co/t/shards-failed-in-kibana/310559/3 "2022-07-26T09:26:56Z")

</div>

Thanks for the replay!  
yes i've re setup with this configuration

```auto
filebeat.inputs:
- type: log
  id: my-filestream-id
  enabled: false 
    - /var/log/*.log

filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true

setup.template.settings:
 index.number_of_shards: 1

setup.dashboards.enabled: true

setup.kibana:
   host: "http://a.d.d.r:5601"

output.elasticsearch:
   hosts: ["http://a.d.d.r:9200"]
  username: "username"
  password: "password"

processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

```

Then i used filebeat setup -e and everything seems to be right 🤦

Best regard

---

<div class="post-metadata">

**Author:** ![OoO](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ooo/32/103296_2.png) [@OoO](https://discuss.elastic.co/u/OoO)\
**Post date:** [August 16, 2022, 4:27pm UTC](https://discuss.elastic.co/t/shards-failed-in-kibana/310559/4 "2022-08-16T16:27:34Z")

</div>

Hello ( \>﹏\<。)  
Someone can help pls?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2022, 4:28pm UTC](https://discuss.elastic.co/t/shards-failed-in-kibana/310559/5 "2022-09-13T16:28:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
