# Too many shards

**URL:** <https://discuss.elastic.co/t/too-many-shards/59668>\
**Category:** Elasticsearch\
**Created:** [September 2, 2016, 1:19pm UTC](https://discuss.elastic.co/t/too-many-shards/59668 "2016-09-02T13:19:19Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![veve90](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/veve90/32/6517_2.png) [@veve90](https://discuss.elastic.co/u/veve90)\
**Post date:** [September 2, 2016, 1:19pm UTC](https://discuss.elastic.co/t/too-many-shards/59668/1 "2016-09-02T13:19:19Z")

</div>

Hello,

For one of the kibana queries I have the folowing error:

> Error: Request to Elasticsearch failed: {"error":{"root\_cause":[{"type":"illegal\_argument\_exception","reason":"Trying to query 1230 shards, which is over the limit of 1000. This limit exists because querying many shards at the same time can make the job of the coordinating node very CPU and/or memory intensive. It is usually a better idea to have a smaller number of larger shards. Update [action.search.shard\_count.limit] to a greater value if you really want to query that many shards at the same time."}],"type":"illegal\_argument\_exception","reason":"Trying to query 1230 shards, which is over the limit of 1000. This limit exists because querying many shards at the same time can make the job of the coordinating node very CPU and/or memory intensive. It is usually a better idea to have a smaller number of larger shards. Update [action.search.shard\_count.limit] to a greater value if you really want to query that many shards at the same time."}}  
> at [http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:93:4184](http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:93:4184)  
> at Function.Promise.try ([http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:93:13507](http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:93:13507))  
> at [http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:93:12971](http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:93:12971)  
> at Array.map (native)  
> at Function.Promise.map ([http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:93:12926](http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:93:12926))  
> at callResponseHandlers ([http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:93:3796](http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:93:3796))  
> at [http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:92:24284](http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:92:24284)  
> at processQueue ([http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:38:23627](http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:38:23627))  
> at [http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:38:23894](http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:38:23894)  
> at Scope.$eval ([http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:39:4619](http://192.xxx.xx.xx/bundles/commons.bundle.js?v=11107:39:4619))

Where can I set this "action.search.shard\_count.limit" parameter?  
Is there a way to merge my shards?

Thank you!

Alina GHERMAN

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 3, 2016, 7:43pm UTC](https://discuss.elastic.co/t/too-many-shards/59668/2 "2016-09-03T19:43:36Z")

</div>

You can use the reindex API to copy the contents of multiple indexes into a single destination index, after which you can delete the old indexes.

How have you reached so many shards in the first place? There are probably things to do to prevent this from getting worse.

---

<div class="post-metadata">

**Author:** ![veve90](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/veve90/32/6517_2.png) [@veve90](https://discuss.elastic.co/u/veve90)\
**Post date:** [September 4, 2016, 6:07pm UTC](https://discuss.elastic.co/t/too-many-shards/59668/3 "2016-09-04T18:07:54Z")

</div>

I have one index a day since january, and since by default there are 5 shards per index... ☹

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 4, 2016, 6:16pm UTC](https://discuss.elastic.co/t/too-many-shards/59668/4 "2016-09-04T18:16:17Z")

</div>

Unless a daily index contains, say, 100 GB data you don't need five shards. A single shard will do fine up to a few tens of gigabytes.

---

<div class="post-metadata">

**Author:** ![kstaken](https://avatars.discourse-cdn.com/v4/letter/k/e68b1a/32.png) [@kstaken](https://discuss.elastic.co/u/kstaken)\
**Post date:** [September 8, 2016, 9:58pm UTC](https://discuss.elastic.co/t/too-many-shards/59668/5 "2016-09-08T21:58:14Z")

</div>

> [@veve90](#):
>
> action.search.shard\_count.limit

What version of elasticsearch has this limit? Is it new in 5.0?

Kimbro

---

<div class="post-metadata">

**Author:** ![veve90](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/veve90/32/6517_2.png) [@veve90](https://discuss.elastic.co/u/veve90)\
**Post date:** [September 9, 2016, 12:29pm UTC](https://discuss.elastic.co/t/too-many-shards/59668/6 "2016-09-09T12:29:25Z")

</div>

Yes, 5.0.0-alpha1

---

<div class="post-metadata">

**Author:** ![Hamsaraj](https://avatars.discourse-cdn.com/v4/letter/h/5e9695/32.png) [@Hamsaraj](https://discuss.elastic.co/u/Hamsaraj)\
**Post date:** [October 13, 2016, 5:02am UTC](https://discuss.elastic.co/t/too-many-shards/59668/7 "2016-10-13T05:02:52Z")

</div>

Can someone please help locate the file containing this parameter  
action.search.shard\_count.limit

I have a single log file of around 3.2 GB which I am trying to parse using a single Elasticsearch node and i get similar error. This is just a test setup and I am using ElasticSearch 5.0 beta version for this setup.

**Error** : Discover: Trying to query 2051 shards, which is over the limit of 1000. This limit exists because querying many shards at the same time can make the job of the coordinating node very CPU and/or memory intensive. It is usually a better idea to have a smaller number of larger shards. Update [action.search.shard\_count.limit] to a greater value if you really want to query that many shards at the same time.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 13, 2016, 5:26am UTC](https://discuss.elastic.co/t/too-many-shards/59668/8 "2016-10-13T05:26:46Z")

</div>

@Hamsaraj, please start a new thread for your unrelated question.

---

<div class="post-metadata">

**Author:** ![Orsius](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orsius/32/13646_2.png) [@Orsius](https://discuss.elastic.co/u/Orsius)\
**Post date:** [December 6, 2016, 2:56pm UTC](https://discuss.elastic.co/t/too-many-shards/59668/9 "2016-12-06T14:56:16Z")

</div>

Thank you all for your replies on this topic, they helped me fix my problem. 😉

If it may help others, I encountered the same issue on a “monitoring” elastic-cluster that received information from production nodes (metricsbeat … ) and others sources; Simply put some automate indices purge with “[curator CLI](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/ex_delete_indices.html)” in place helped me to keep thing straight without modifying the [elasticsearch.yml](https://www.elastic.co/guide/en/elasticsearch/reference/5.0/breaking_50_search_changes.html#_search_shard_limit) file on my cluster; (understand without having to reboot the service and therefore keep things up and running).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:05pm UTC](https://discuss.elastic.co/t/too-many-shards/59668/10 "2017-07-05T22:05:15Z")

</div>


