# TSVB table results greater than 12 hours results in an error

**URL:** <https://discuss.elastic.co/t/tsvb-table-results-greater-than-12-hours-results-in-an-error/284253>\
**Category:** Kibana\
**Created:** [September 15, 2021, 7:11am UTC](https://discuss.elastic.co/t/tsvb-table-results-greater-than-12-hours-results-in-an-error/284253 "2021-09-15T07:11:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![fidsamurai](https://avatars.discourse-cdn.com/v4/letter/f/a5b964/32.png) [@fidsamurai](https://discuss.elastic.co/u/fidsamurai)\
**Post date:** [September 15, 2021, 7:11am UTC](https://discuss.elastic.co/t/tsvb-table-results-greater-than-12-hours-results-in-an-error/284253/1 "2021-09-15T07:11:16Z")

</div>

Hi All,

I have a bit of a strange issue -  
I have created a TSVB table with 8 columns.  
3 are normal count columns.  
The remaining 5 are filter ratios.

The weird scenario is that if we keep the time to "Last 12 hours", we get results.  
However if we go beyond 12 hours we get no results.

Steps I've tried -  
Increased the Kibana Search timeout to 3000000.  
Increased the TSVB maxbuckets to 6000

Please help.  
ELK - 7.13.4

---

<div class="post-metadata">

**Author:** ![John\_Guzman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_guzman/32/83587_2.png) [@John\_Guzman](https://discuss.elastic.co/u/John_Guzman)\
**Post date:** [September 16, 2021, 2:24am UTC](https://discuss.elastic.co/t/tsvb-table-results-greater-than-12-hours-results-in-an-error/284253/2 "2021-09-16T02:24:44Z")

</div>

Hello!

The problem could be the "data timerange mode" option in the "Panel options" panel. Use the "Entire time range" option so the graph would be shown as the metric calculations of all the data on the date range chosen in the time picker. With the "Last value" option the graph will show only the data of the last bucket, that sometimes this could be empty

Regards

---

<div class="post-metadata">

**Author:** ![fidsamurai](https://avatars.discourse-cdn.com/v4/letter/f/a5b964/32.png) [@fidsamurai](https://discuss.elastic.co/u/fidsamurai)\
**Post date:** [September 16, 2021, 3:36am UTC](https://discuss.elastic.co/t/tsvb-table-results-greater-than-12-hours-results-in-an-error/284253/3 "2021-09-16T03:36:05Z")

</div>

Hi @John_Guzman,

I'm already using the "Entire time range" option.  
I do have something like 75 million documents in 24 hours though, is there a data fetching limit or a timeout that could be causing this issue?

Edit - Also I don't know if this makes any actual difference but I'm using a TSVB table not a graph.

---

<div class="post-metadata">

**Author:** ![John\_Guzman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_guzman/32/83587_2.png) [@John\_Guzman](https://discuss.elastic.co/u/John_Guzman)\
**Post date:** [September 16, 2021, 2:50pm UTC](https://discuss.elastic.co/t/tsvb-table-results-greater-than-12-hours-results-in-an-error/284253/4 "2021-09-16T14:50:27Z")

</div>

Uhmm. Elasticsearch or Kibana logs reporting something? There is no limit, but in large request that an index can't handle usally appears a notification with the timeout error in Kibana.

---

<div class="post-metadata">

**Author:** ![fidsamurai](https://avatars.discourse-cdn.com/v4/letter/f/a5b964/32.png) [@fidsamurai](https://discuss.elastic.co/u/fidsamurai)\
**Post date:** [September 17, 2021, 5:19am UTC](https://discuss.elastic.co/t/tsvb-table-results-greater-than-12-hours-results-in-an-error/284253/5 "2021-09-17T05:19:37Z")

</div>

I'm attaching the screenshots of the error -

1. Dashboard error(I've had to redact the data however I've left the columns)

 ![Automated-Dash-Error-18-Hours](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d4145f539e30277361212c268b7d613f1fb0174f.jpeg)

1. TSVB error -

 ![Automated-Dash-TSVB-Error-18-Hours](https://us1.discourse-cdn.com/elastic/original/3X/4/9/49d43e9e5f0bccfb3b13fe6824aa7d21a1ab1dca.jpeg)

Also we get a pretty dramatic spike in the CPU from 30% to 90%.  
Elasticsearch and Kibana are on the same server and they communicate on their default ports.

Kibana logs -  
`["error","plugins","dataEnhanced","data_enhanced"],"pid":6660,"message":"Error while updating search session 7e3db2df-c4c0-4070-908c-acd62c31b802: Saved object [search-session/7e3db2df-c4c0-4070-908c-acd62c31b802] conflict"}`

That's the only log I could get which could be an error.  
Nothing in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![fidsamurai](https://avatars.discourse-cdn.com/v4/letter/f/a5b964/32.png) [@fidsamurai](https://discuss.elastic.co/u/fidsamurai)\
**Post date:** [October 1, 2021, 4:05am UTC](https://discuss.elastic.co/t/tsvb-table-results-greater-than-12-hours-results-in-an-error/284253/6 "2021-10-01T04:05:52Z")

</div>

Can someone help with this please?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2021, 4:06am UTC](https://discuss.elastic.co/t/tsvb-table-results-greater-than-12-hours-results-in-an-error/284253/7 "2021-10-29T04:06:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
