# 413 Request Entity Too Large - kibana error

**URL:** <https://discuss.elastic.co/t/413-request-entity-too-large-kibana-error/209399>\
**Category:** Kibana\
**Created:** [November 26, 2019, 12:55am UTC](https://discuss.elastic.co/t/413-request-entity-too-large-kibana-error/209399 "2019-11-26T00:55:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![aveek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aveek/32/58554_2.png) [@aveek](https://discuss.elastic.co/u/aveek)\
**Post date:** [November 26, 2019, 12:55am UTC](https://discuss.elastic.co/t/413-request-entity-too-large-kibana-error/209399/1 "2019-11-26T00:55:38Z")

</div>

Hi ,

Elastic Stack version: 7.2.0

We are using logstash to parse data and create custom fields. We rely on _dynamic mapping_ to auto detect the new fields and add them to the index template. We have more than 1000 new fields added though the logstash pipeline. The data is indexed in elasticsearch successfully,however when we try to search the index in kibana discover tab we are getting 413 in kibana. Please see screenshot attached.

 ![00%20PM%20-%20Display%201](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2e1aff43f0b9e32318303a0ef7e8b3ed36a5fce2.png) .

`Status Code: 413 Request Entity Too Large`

Also we can also see the following error in kibana logs.

```
"rejected execution of processing of [57480853][indices:data/write/bulk[s][
p]]: request: BulkShardRequest [[.kibana_1][0]] containing [index {[.kibana][_doc][index-pattern:metricbeat-*], **source[n/a, actual length: [1.1mb], max length: 2kb]}]** blocking until refresh, target allocation id: 
ur3EAwZhTU6jb0ixKb7ViA, primary term: 31 on EsThreadPoolExecutor[name = utilities-b3-7/write, queue capacity = 200, org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor@429ef742[Running, pool size = 6, ac
tive threads = 6, queued tasks = 242, completed tasks = 43490935]]\\\"},\\\"status\\\":429}\"}\n at respond (/usr/share/kibana/node_modules/elasticsearch/src/lib/transport.js:315:15)\n at checkRespForFailure
 (/usr/share/kibana/node_modules/elasticsearch/src/lib/transport.js:274:7)\n at HttpConnector.<anonymous> (/usr/share/kibana/node_modules/elasticsearch/src/lib/connectors/http.js:166:7)\n at IncomingMessage.
wrapper (/usr/share/kibana/node_modules/elasticsearch/node_modules/lodash/lodash.js:4935:19)\n at IncomingMessage.emit (events.js:194:15)\n at endReadableNT (_stream_readable.js:1103:12)\n at process._tic
kCallback (internal/process/next_tick.js:63:19)"},"url":{"protocol":null,"slashes":null,"auth":null,"host":null,"port":null,"hostname":null,"hash":null,"search":null,"query":{},"pathname":"/api/saved_objects/index-pattern/metricbeat-*","path":"/api/saved_objects/index-pattern/metricbeat-*","href":"/api/saved_objects/index-pattern/metricbeat-*"},"message":"rejected execution of processing of [57480853][indices:data/write/bulk[s][p]]: request: BulkShardRequest [[.kibana_1][0]] containing [index {[.kibana][_doc][index-pattern:metricbeat-*], source[n/a, actual length: [1.1mb], max length: 2kb]}] blocking until refresh, target allocation id: ur3EAwZhTU6jb0ixKb7ViA, primary term: 31 on EsThreadPoolExecutor[name = utilities-b3-7/write, queue capacity = 200, org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor@429ef742[Running, pool size =
 6, active threads = 6, queued tasks = 242, completed tasks = 43490935]]: [remote_transport_exception] [utilities-b3-7][10.2.64.7:9300][indices:data/write/update[s]]"}

```

We have increased the **server.maxPayloadBytes** to "2097152" in kibanal.yml , **http.max\_header\_size** to "2mb" in elasticsearch.yml and **client\_max\_body\_size** to "2M" in nginx.conf but kibana is still returning "413 Request Entity Too Large" response .  
**Response on browser**

```
<html>
<head><title>413 Request Entity Too Large</title></head>
<body bgcolor="white">
<center><h1>413 Request Entity Too Large</h1></center>
<hr><center>nginx/1.7.8</center>
</body>
</html>

```

Anyone has any recommendations on how to fix this issue. Any help would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![christophilus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christophilus/32/42991_2.png) [@christophilus](https://discuss.elastic.co/u/christophilus)\
**Post date:** [November 26, 2019, 4:13pm UTC](https://discuss.elastic.co/t/413-request-entity-too-large-kibana-error/209399/2 "2019-11-26T16:13:55Z")

</div>

I think there are a couple of things you could try. First, you can change how many documents Discover requests by going to advanced settings, and setting the `discover:sampleSize` parameter:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e869f331bfe6ea76143944e7e4bd3845f049f5e9.png)

That'll probably solve it. But another thing you could do is, if there are some really big fields in your documents, you can create a source filter in your index pattern to remove the offending fields from the index pattern. Discover will then refrain from loading those fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2019, 4:13pm UTC](https://discuss.elastic.co/t/413-request-entity-too-large-kibana-error/209399/3 "2019-12-24T16:13:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
