# Any way to limit field length?

**URL:** <https://discuss.elastic.co/t/any-way-to-limit-field-length/54734>\
**Category:** Logstash\
**Created:** [July 5, 2016, 1:06pm UTC](https://discuss.elastic.co/t/any-way-to-limit-field-length/54734 "2016-07-05T13:06:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Benoit-DunandLaisin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benoit-dunandlaisin/32/10726_2.png) [@Benoit-DunandLaisin](https://discuss.elastic.co/u/Benoit-DunandLaisin)\
**Post date:** [July 5, 2016, 1:06pm UTC](https://discuss.elastic.co/t/any-way-to-limit-field-length/54734/1 "2016-07-05T13:06:23Z")

</div>

Hi,

I sometimes receive messages that are huge... (719939 bytes) and indexation to elasticsearch failed with a max\_bytes\_length\_exceeded\_exception (max limit is 32766 bytes).  
I want to detect those messages in kibana, so I would like to do with logstash something like that:

if len(message) \> 10000 {  
message = message[0:10000] // get only the first bytes  
set tags =\> ["long message"]  
}

However I didn't find that kind of filter.  
Did I miss something?

Regards.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 5, 2016, 6:15pm UTC](https://discuss.elastic.co/t/any-way-to-limit-field-length/54734/2 "2016-07-05T18:15:45Z")

</div>

I don't believe there is such a filter, but it would be easy to write a custom ruby filter. Something like

```nohighlight
ruby {
  code => "
    event['message'] = event['message'][0..9999] if event['message'].length > 10000
    event.tag 'long message'
  "
}

```

should work. You can probably drop the conditional:

```nohighlight
ruby {
  code => "
    event['message'] = event['message'][0..9999]
    event.tag 'long message'
  "
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 5, 2016, 8:46pm UTC](https://discuss.elastic.co/t/any-way-to-limit-field-length/54734/3 "2016-07-05T20:46:35Z")

</div>

You can do this in ES via the mappings too, see [https://www.elastic.co/guide/en/elasticsearch/reference/2.3/ignore-above.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.3/ignore-above.html)

---

<div class="post-metadata">

**Author:** ![Benoit-DunandLaisin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benoit-dunandlaisin/32/10726_2.png) [@Benoit-DunandLaisin](https://discuss.elastic.co/u/Benoit-DunandLaisin)\
**Post date:** [July 6, 2016, 7:33am UTC](https://discuss.elastic.co/t/any-way-to-limit-field-length/54734/4 "2016-07-06T07:33:43Z")

</div>

Wow, thanks you two.  
This is very helpful.

---

<div class="post-metadata">

**Author:** ![PhaedrusTheGreek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phaedrusthegreek/32/4884_2.png) [@PhaedrusTheGreek](https://discuss.elastic.co/u/PhaedrusTheGreek)\
**Post date:** [March 24, 2017, 2:22pm UTC](https://discuss.elastic.co/t/any-way-to-limit-field-length/54734/5 "2017-03-24T14:22:17Z")

</div>

See [Truncate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-truncate.html) and [Range](https://www.elastic.co/guide/en/logstash/current/plugins-filters-range.html#plugins-filters-range-ranges) filters

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:27am UTC](https://discuss.elastic.co/t/any-way-to-limit-field-length/54734/6 "2017-07-06T04:27:35Z")

</div>


