# Elasticsearch PivotAggregationSearch errors after upgrade to 4.1 ES 7.14

**URL:** https://community.graylog.org/t/elasticsearch-pivotaggregationsearch-errors-after-upgrade-to-4-1-es-7-14/21006
**Category:** Graylog Central (peer support)
**Created:** [August 26, 2021, 7:42pm UTC](https://community.graylog.org/t/elasticsearch-pivotaggregationsearch-errors-after-upgrade-to-4-1-es-7-14/21006 "2021-08-26T19:42:41Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![tgarons](https://avatars.discourse-cdn.com/v4/letter/t/49beb7/32.png) [@tgarons](https://community.graylog.org/u/tgarons)
#### Post date: [August 26, 2021, 7:42pm UTC](https://community.graylog.org/t/elasticsearch-pivotaggregationsearch-errors-after-upgrade-to-4-1-es-7-14/21006/1 "2021-08-26T19:42:41Z")

</div>

## Description of your problem

After a more or less successful upgrade to graylog 4.1 and elasticsearch 7.14 we are seeing a lot of the following errors in the graylog server log:  
ERROR [PivotAggregationSearch] Aggregation search query returned an error: Elasticsearch exception [type=illegal\_argument\_exception, reason=maxSize must be \>= 0 and \< 2147483631; got: 2147483647]

There are no corresponding errors in the elasticsearch log.

Does anyone know what the source of these error is and how to fix them?

### Operating system information

- Ubuntu
- 

### Package versions

- Graylog  
4.1.3+9d79c05

- MongoDB  
v3.6.23

- Elasticsearch  
7.14

---

<div class="post-metadata">

### Author: ![ttsandrew](https://avatars.discourse-cdn.com/v4/letter/t/97f17d/32.png) [@ttsandrew](https://community.graylog.org/u/ttsandrew)
#### Post date: [August 26, 2021, 7:45pm UTC](https://community.graylog.org/t/elasticsearch-pivotaggregationsearch-errors-after-upgrade-to-4-1-es-7-14/21006/2 "2021-08-26T19:45:17Z")

</div>

Hello @tgarons,

Unfortunately Elasticsearch 7.14 isn’t supported.

> [@Graylog 4.x and Elasticsearch 7.11.x?](https://community.graylog.org/t/graylog-4-x-and-elasticsearch-7-11-x/19069):
>
> Is anyone running ES 7.11.x with the latest Graylog? I see that 7.10.x is officially supported by I just wonder if that’s because of when the document was authored. [https://docs.graylog.org/en/4.0/pages/configuration/elasticsearch.html#elasticsearch-versions](https://docs.graylog.org/en/4.0/pages/configuration/elasticsearch.html#elasticsearch-versions)@aaronsachs

[https://docs.graylog.org/en/4.0/pages/configuration/elasticsearch.html#elasticsearch-versions](https://docs.graylog.org/en/4.0/pages/configuration/elasticsearch.html#elasticsearch-versions)

---

<div class="post-metadata">

### Author: ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)
#### Post date: [August 26, 2021, 8:54pm UTC](https://community.graylog.org/t/elasticsearch-pivotaggregationsearch-errors-after-upgrade-to-4-1-es-7-14/21006/3 "2021-08-26T20:54:10Z")

</div>

We (… OK, **I** 🤪…) accidentally upgraded elasticsearch to 7.14 and I am seeing those errors in my Graylog log as well. I also see that my index registers as having been created 52 years ago (punch cards, I am sure!) From what I can tell so far this results in widgets on dashboards failing to load properly on occasion - usually a single refresh will fix that. Had I been a bit more astute I would have caught that we shouldn’t upgrade Elastic when doing a general Ubuntu upgrade … and I would have [put a hold on Elastic](https://help.ubuntu.com/community/PinningHowto) to 7.10.

I was considering adding a 7.10 version to the cluster, then dropping/rebuilding the 7.14 machines but I am not sure it is possible - Elastic cluster may choke on versioning or data may get lost/corrupted. Still…it would be a good exercise to go though though… 🤔

---

<div class="post-metadata">

### Author: ![ttsandrew](https://avatars.discourse-cdn.com/v4/letter/t/97f17d/32.png) [@ttsandrew](https://community.graylog.org/u/ttsandrew)
#### Post date: [August 26, 2021, 9:08pm UTC](https://community.graylog.org/t/elasticsearch-pivotaggregationsearch-errors-after-upgrade-to-4-1-es-7-14/21006/4 "2021-08-26T21:08:39Z")

</div>

At the very least a package hold to prevent future accidental upgrades is warranted, which is what I did after the upgrade to 7.12.

---

<div class="post-metadata">

### Author: ![tgarons](https://avatars.discourse-cdn.com/v4/letter/t/49beb7/32.png) [@tgarons](https://community.graylog.org/u/tgarons)
#### Post date: [August 26, 2021, 9:39pm UTC](https://community.graylog.org/t/elasticsearch-pivotaggregationsearch-errors-after-upgrade-to-4-1-es-7-14/21006/5 "2021-08-26T21:39:39Z")

</div>

Let me know how adding a 7.10 node works out for you. As I totally hosed three months worth of data when I upgraded from 5.6-\>6.8-\>7.14 I may just start from scratch, but if there was a smoother way to get a supported release that would be great. As it is things seem to be working for the most part aside from those errors—the stuff I care about—streams, alerts, plugin configurations all seem functional. If 7.14 is on the road map I’m willing to live with the errors for a while.  
Tom

---

<div class="post-metadata">

### Author: ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)
#### Post date: [August 26, 2021, 11:42pm UTC](https://community.graylog.org/t/elasticsearch-pivotaggregationsearch-errors-after-upgrade-to-4-1-es-7-14/21006/6 "2021-08-26T23:42:01Z")

</div>

Hello,

I had this happen to myself a couple times and what I started doing after a install was pinning by repository name.

[https://itectec.com/ubuntu/ubuntu-pinning-package-using-own-repository-and-apt-get/#:~:text=Solution%202%20(using%20Pinning)](https://itectec.com/ubuntu/ubuntu-pinning-package-using-own-repository-and-apt-get/#:~:text=Solution%202%20(using%20Pinning))

---

<div class="post-metadata">

### Author: ![rayleigh](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/rayleigh/32/9833_2.png) [@rayleigh](https://community.graylog.org/u/rayleigh)
#### Post date: [August 30, 2021, 8:59am UTC](https://community.graylog.org/t/elasticsearch-pivotaggregationsearch-errors-after-upgrade-to-4-1-es-7-14/21006/7 "2021-08-30T08:59:15Z")

</div>

Same problem here, everything was working fine until I add a third graylog node to complete my cluster,

now I get a lot of “ERROR [PivotAggregationSearch]” in my logs resulting to a non working aggregation so now all my alerts with aggregation results won’t work anymore…  
Is there a way to fix this please?

Graylog version: 4.0.11  
ES version: 7.14

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)
#### Post date: [September 13, 2021, 8:59am UTC](https://community.graylog.org/t/elasticsearch-pivotaggregationsearch-errors-after-upgrade-to-4-1-es-7-14/21006/8 "2021-09-13T08:59:46Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
