# Character limit in fields longer then 1024 (truncated with ellipsis)

**URL:** <https://discuss.elastic.co/t/character-limit-in-fields-longer-then-1024-truncated-with-ellipsis/280415>\
**Category:** APM\
**Tags:** dotnet\
**Created:** [August 4, 2021, 10:41am UTC](https://discuss.elastic.co/t/character-limit-in-fields-longer-then-1024-truncated-with-ellipsis/280415 "2021-08-04T10:41:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![GiladanoN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/giladanon/32/92522_2.png) [@GiladanoN](https://discuss.elastic.co/u/GiladanoN)\
**Post date:** [August 4, 2021, 10:41am UTC](https://discuss.elastic.co/t/character-limit-in-fields-longer-then-1024-truncated-with-ellipsis/280415/1 "2021-08-04T10:41:41Z")

</div>

Hi/

i'm having an issue with **certain logs fields being longer than 1024 chars**.  
When searching for the relevant log it comes up, but the relevant field is truncated, and the remainder of the text is replaced with an ellipsis character.

(as in: `field/keyword: "loglog .. .. log…"`  
where the `'…'` char appears as the 1025 char in my log field).

We're using an APM Agent in our .Net application (_classic / aspx_),  
and are querying the data **using kibana's "discover" area**.

_Note_- we're not getting errors when posting logs, but rather that they come up "partial" when we're querying them.

**From reading up on this in various places:**

- [Increase setCustomContext context character limit](https://discuss.elastic.co/t/increase-setcustomcontext-context-character-limit/173818)
- [Metadata | APM Server Reference [7.14] | Elastic](https://www.elastic.co/guide/en/apm/server/current/metadata-api.html#metadata-schema)
- [4096 characters input limitation! missing part of logs in message field](https://discuss.elastic.co/t/4096-characters-input-limitation-missing-part-of-logs-in-message-field/217522)

This would _seem_ to be configurable somewhere somehow. Unfortunately i couldn't figure out where this change should be applied --- Tried looking at our .Net app's `web.config` file, the `.cs` file where we implement our `Application_Start()` and the relevant `Agent` APM instance....

Couldn't find a relevant configuration option in any of them, like a `truncateStringsAt` or sanitization options, nor a `maxLength` like property for the server's json config...

**Where is this limitation coming from?**  
Is it a server-side config? (where the logs are sent to?)  
Is there some other config on the App / Object's side that i'm missing or unfamiliar with?

Any help / pointers would be greatly appreciated !

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [August 5, 2021, 2:56am UTC](https://discuss.elastic.co/t/character-limit-in-fields-longer-then-1024-truncated-with-ellipsis/280415/2 "2021-08-05T02:56:14Z")

</div>

Hello,

Can you please check the mapping of the field which is getting truncated? Please take a look at this post and see if your issue is similar?

> [@Long messages not displayed](https://discuss.elastic.co/t/long-messages-not-displayed/138922):
>
> Hi All, I Have problem when I try to display long message 1000 caractere in kibana. I use a data table so, some message is display but the long message wasn't display. Do you know if it have a limit caractere to display message ? Thanks in advance BR

Thanks  
Bhavya

---

<div class="post-metadata">

**Author:** ![GiladanoN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/giladanon/32/92522_2.png) [@GiladanoN](https://discuss.elastic.co/u/GiladanoN)\
**Post date:** [August 5, 2021, 10:29am UTC](https://discuss.elastic.co/t/character-limit-in-fields-longer-then-1024-truncated-with-ellipsis/280415/3 "2021-08-05T10:29:06Z")

</div>

Hi @bhavyarm , thank you for the reply!

Will check the "truncate:maxHeight" setting on the server's advanced settings.  
However, I think the situation is different in 2 ways from the post provided as a reference.

1st, the interface used by the user in that post is the "Dashboard", where as we're using the "Discover" mechanism to run our queries.

2nd, that user's issue seems to revolve around FINDING the info in question, due to a configurable limit, whilst our issue is with READING said data, which as mention seems to be "cut off" at the 1024th char.

so i'm unsure if this will provide a solution, but will update back promptly once we change it.

* * *

in regard to your request we "check the mapping of the field", could you point me towards any resource explaining how to access these mappings? (are they maintained on the sending / receiving side, how to i check them directly etc...)

and thanks again ! 😃

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [August 5, 2021, 2:25pm UTC](https://discuss.elastic.co/t/character-limit-in-fields-longer-then-1024-truncated-with-ellipsis/280415/4 "2021-08-05T14:25:09Z")

</div>

Hello,

Here you go to check the mapping - [Get mapping API | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html)

I also got feedback from an engineer about having to ask the apm to team to take a look at this. I am transferring your post to them.

Thanks  
Bhavya

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [August 11, 2021, 2:03am UTC](https://discuss.elastic.co/t/character-limit-in-fields-longer-then-1024-truncated-with-ellipsis/280415/5 "2021-08-11T02:03:33Z")

</div>

Hi @GiladanoN,

The APM agents send data to APM server in formats that conform to JSON schemata. For example, the schema for spans is

> <https://github.com/elastic/apm-server/blob/cfc9d4c8043d489269e8d6678b6a567505962b9f/docs/spec/v2/span.json>

The schema defines a max length of 1024 for many of the string fields, in order to keep APM index sizes from growing large.

The .NET agent (and I think other agents too) hard limit the size of properties on trace types like `Span` and `Transaction` in line with the schema, and add an ellipsis to indicate a value has been truncated. Generally, fields with a max length are not configurable.

Are there particular fields you're using where max length configuration would be useful?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2021, 2:04am UTC](https://discuss.elastic.co/t/character-limit-in-fields-longer-then-1024-truncated-with-ellipsis/280415/6 "2021-09-08T02:04:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
