# Will kibana work if i am trying to index a file of 6.5 GB having 3 million records

**URL:** <https://discuss.elastic.co/t/will-kibana-work-if-i-am-trying-to-index-a-file-of-6-5-gb-having-3-million-records/100065>\
**Category:** Kibana\
**Created:** [September 11, 2017, 1:31pm UTC](https://discuss.elastic.co/t/will-kibana-work-if-i-am-trying-to-index-a-file-of-6-5-gb-having-3-million-records/100065 "2017-09-11T13:31:55Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sudi\_2611](https://avatars.discourse-cdn.com/v4/letter/s/47e85d/32.png) [@sudi\_2611](https://discuss.elastic.co/u/sudi_2611)\
**Post date:** [September 11, 2017, 1:31pm UTC](https://discuss.elastic.co/t/will-kibana-work-if-i-am-trying-to-index-a-file-of-6-5-gb-having-3-million-records/100065/1 "2017-09-11T13:31:55Z")

</div>

Hi Team,

Will kibana work if i am trying to index a file of 6.5 GB having 3 million records.  
When i try to query the data i get 3000ms request timed out error and application status goes down having status as red

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [September 11, 2017, 7:57pm UTC](https://discuss.elastic.co/t/will-kibana-work-if-i-am-trying-to-index-a-file-of-6-5-gb-having-3-million-records/100065/2 "2017-09-11T19:57:42Z")

</div>

Shouldn't be a problem. What does the query look like? What happens if you run the same query directly against elasticsearch?

---

<div class="post-metadata">

**Author:** ![sudi\_2611](https://avatars.discourse-cdn.com/v4/letter/s/47e85d/32.png) [@sudi\_2611](https://discuss.elastic.co/u/sudi_2611)\
**Post date:** [September 11, 2017, 8:05pm UTC](https://discuss.elastic.co/t/will-kibana-work-if-i-am-trying-to-index-a-file-of-6-5-gb-having-3-million-records/100065/3 "2017-09-11T20:05:24Z")

</div>

> [@Bargs](#):
>
> What does the query look like

I get the following error  
{  
"error": {  
"root\_cause": [  
{  
"type": "illegal\_argument\_exception",  
"reason": "Trying to query 1469 shards, which is over the limit of 1000. This limit exists because querying many shards at the same time can make the job of the coordinating node very CPU and/or memory intensive. It is usually a better idea to have a smaller number of larger shards. Update [action.search.shard\_count.limit] to a greater value if you really want to query that many shards at the same time."  
}  
],  
"type": "illegal\_argument\_exception",  
"reason": "Trying to query 1469 shards, which is over the limit of 1000. This limit exists because querying many shards at the same time can make the job of the coordinating node very CPU and/or memory intensive. It is usually a better idea to have a smaller number of larger shards. Update [action.search.shard\_count.limit] to a greater value if you really want to query that many shards at the same time."  
},  
"status": 400  
}

query is:  
GET \_search  
{  
"query": {  
"match\_all": {}  
}  
}

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [September 11, 2017, 8:33pm UTC](https://discuss.elastic.co/t/will-kibana-work-if-i-am-trying-to-index-a-file-of-6-5-gb-having-3-million-records/100065/4 "2017-09-11T20:33:50Z")

</div>

Seems like a lot of shards. How many indices are you creating, and how many shards per index?

---

<div class="post-metadata">

**Author:** ![mujtabahussain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mujtabahussain/32/17514_2.png) [@mujtabahussain](https://discuss.elastic.co/u/mujtabahussain)\
**Post date:** [September 12, 2017, 1:47am UTC](https://discuss.elastic.co/t/will-kibana-work-if-i-am-trying-to-index-a-file-of-6-5-gb-having-3-million-records/100065/5 "2017-09-12T01:47:49Z")

</div>

I recommend reducing the number of shards using `_shrink` and then seeing if the query works.

---

<div class="post-metadata">

**Author:** ![sudi\_2611](https://avatars.discourse-cdn.com/v4/letter/s/47e85d/32.png) [@sudi\_2611](https://discuss.elastic.co/u/sudi_2611)\
**Post date:** [September 12, 2017, 5:47pm UTC](https://discuss.elastic.co/t/will-kibana-work-if-i-am-trying-to-index-a-file-of-6-5-gb-having-3-million-records/100065/6 "2017-09-12T17:47:47Z")

</div>

Hi,

I am not sure about shards..i have my data in logstash which is filtered and output config file is as follows:  
output {  
if [type] == "fsimagedaily" {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "fsimage-%{+YYYY.MM.dd}"  
}  
}  
else {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}  
}

When i navigate to kibana UI it opens up but in management index patter tab i see the below:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/0/40f467e4cc77b19ce10616bded3728c04ba92918.png)

and in dev tools tab i get the above error pasted not sure where i am going wrong..

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [September 13, 2017, 2:21pm UTC](https://discuss.elastic.co/t/will-kibana-work-if-i-am-trying-to-index-a-file-of-6-5-gb-having-3-million-records/100065/7 "2017-09-13T14:21:30Z")

</div>

Just to clarify, are you saying that when you visit the index pattern creation page in Kibana, you get the error pasted above? Where do you see the error? In your _browser's_ dev tools?

Or are you getting that error when running a query in _kibana's_ Dev Tools app?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2017, 5:43pm UTC](https://discuss.elastic.co/t/will-kibana-work-if-i-am-trying-to-index-a-file-of-6-5-gb-having-3-million-records/100065/10 "2017-10-11T17:43:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
