# Visualize: socket hangup

**URL:** <https://discuss.elastic.co/t/visualize-socket-hangup/209020>\
**Category:** Kibana\
**Created:** [November 22, 2019, 6:44am UTC](https://discuss.elastic.co/t/visualize-socket-hangup/209020 "2019-11-22T06:44:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![babarsiddique](https://avatars.discourse-cdn.com/v4/letter/b/53a042/32.png) [@babarsiddique](https://discuss.elastic.co/u/babarsiddique)\
**Post date:** [November 22, 2019, 6:44am UTC](https://discuss.elastic.co/t/visualize-socket-hangup/209020/1 "2019-11-22T06:44:18Z")

</div>

```
Error: Bad Gateway
        at respond (http://xxx.xxx.xxx:5000/bundles/kibana.bundle.js?v=15543:13:2730)
        ........

```

Opening kibana's dashboard stopped the elasticsearch master and elasticsearch health goes from green to RED. It happens whenever the shards are more than approx 12000. Below this value dashboard works fine.

Anyone who can help me to resolve this issue?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [November 22, 2019, 4:34pm UTC](https://discuss.elastic.co/t/visualize-socket-hangup/209020/2 "2019-11-22T16:34:51Z")

</div>

Hey @babarsiddique, it sounds like you're querying too many shards and crashing Elasticsearch. 12,000 seems like a lot of shards. How large are your shards? The general guidance is to keep your shard size between a few GB and a few tens of GB per [https://www.elastic.co/guide/en/elasticsearch/reference/7.4/scalability.html#it-depends](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/scalability.html#it-depends).

---

<div class="post-metadata">

**Author:** ![babarsiddique](https://avatars.discourse-cdn.com/v4/letter/b/53a042/32.png) [@babarsiddique](https://discuss.elastic.co/u/babarsiddique)\
**Post date:** [November 25, 2019, 7:05am UTC](https://discuss.elastic.co/t/visualize-socket-hangup/209020/3 "2019-11-25T07:05:39Z")

</div>

Hi @Brandon_Kobel, I have set index\_number\_shards and index\_number\_of\_replicas to 1. Attached screenshot shows the details of my cluster. 1 elasticsearch master and 2 elasticsearch datanode....elasticsearch master is also act as elasticsearch datanode. Heap size for both nodes are 16g.

![Nodes](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d6d6a5c8b6a6600d0dc54668cb2d1930234adb8.png)

 ![shards](https://us1.discourse-cdn.com/elastic/original/3X/4/4/44535b54421ecb1ec48f28067f7247141be3a26c.png)

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [November 25, 2019, 3:10pm UTC](https://discuss.elastic.co/t/visualize-socket-hangup/209020/4 "2019-11-25T15:10:30Z")

</div>

Hey @babarsiddique, those indices are super small, and each of them have 5 primary shards. I'd recommend reducing the primary shards to 1 and no longer user daily indices for this data, and instead using policies to manage index rollover: [https://www.elastic.co/guide/en/elasticsearch/reference/7.4/using-policies-rollover.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/using-policies-rollover.html)

---

<div class="post-metadata">

**Author:** ![babarsiddique](https://avatars.discourse-cdn.com/v4/letter/b/53a042/32.png) [@babarsiddique](https://discuss.elastic.co/u/babarsiddique)\
**Post date:** [November 26, 2019, 6:34am UTC](https://discuss.elastic.co/t/visualize-socket-hangup/209020/5 "2019-11-26T06:34:27Z")

</div>

Thanks @Brandon_Kobel, i have set the index\_number\_of\_shards to 1 and index\_number\_of\_replicas to 1 at the time of installation of elasticsearch but i think it is not creating any effect on indexes. For index rollover i have configured elasticsearch curator which deletes the old indices now i have around 8000 shards but dashboard again crashing the elasticsearch master.

Looking forward to hear from you  
Thanks again!

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [November 26, 2019, 2:31pm UTC](https://discuss.elastic.co/t/visualize-socket-hangup/209020/6 "2019-11-26T14:31:45Z")

</div>

Hey @babarsiddique, I'd recommend opening a new topic over in the [Elastisearch section](https://discuss.elastic.co/c/elasticsearch) asking for advice on how to collapse individual indices into fewer. 8000 shards is still a ton, and executing a search which hits all of them is bound to cause issues.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2019, 2:31pm UTC](https://discuss.elastic.co/t/visualize-socket-hangup/209020/7 "2019-12-24T14:31:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
