# Dead Letter - cannot write event to DLQ: reached maxQueueSize of 2147483648

**URL:** <https://discuss.elastic.co/t/dead-letter-cannot-write-event-to-dlq-reached-maxqueuesize-of-2147483648/239100>\
**Category:** Logstash\
**Created:** [June 29, 2020, 11:25am UTC](https://discuss.elastic.co/t/dead-letter-cannot-write-event-to-dlq-reached-maxqueuesize-of-2147483648/239100 "2020-06-29T11:25:48Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [June 29, 2020, 11:25am UTC](https://discuss.elastic.co/t/dead-letter-cannot-write-event-to-dlq-reached-maxqueuesize-of-2147483648/239100/1 "2020-06-29T11:25:48Z")

</div>

Hi Team,  
I facing syncing issue in Elasticsearch and when i check my logstash log and i observer the below error  
"cannot write event to DLQ: reached maxQueueSize of 2147483648".

whether its causing the syncing issue and how to resolve it.

Can anyone help me on this .

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [June 29, 2020, 12:50pm UTC](https://discuss.elastic.co/t/dead-letter-cannot-write-event-to-dlq-reached-maxqueuesize-of-2147483648/239100/2 "2020-06-29T12:50:04Z")

</div>

Hello Ganesh,

There is an open issue regarding cleaning the deadletterqueue here: [https://github.com/elastic/logstash/issues/8795](https://github.com/elastic/logstash/issues/8795)

If you do not need the data from the deadletter queue you may ignore the error - in this case LogStash does not write to the DLQ anymore.  
But I guess you want to read the data from the DLQ so you would have to:

- Create a Logstash pipeline for extracting the DQL contents
- shutdown Logstash
- remove the files from the DLQ directory
- start LogStash again

A pipeline extracting the contents might look like this(You have to modify the paths and the pipeline id):

```auto
input {
  dead_letter_queue {
    path => "/logserver/data/data-logstash/dead_letter_queue" 
    commit_offsets => true 
    pipeline_id => "dummy" 
  }
}
output {
 file {
   path => "/logserver/applications/logs/dead_letter_queue"
   codec => rubydebug { metadata => true }
 }
}

```

This creates a file named `/logserver/applications/logs/dead_letter_queue` containing the original message and additional information like the reason why it was sent to the DLQ as formatted JSON.

I hope this helps.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [June 29, 2020, 3:09pm UTC](https://discuss.elastic.co/t/dead-letter-cannot-write-event-to-dlq-reached-maxqueuesize-of-2147483648/239100/3 "2020-06-29T15:09:18Z")

</div>

Thanks for your reply @Wolfram_Haussig,

My dead letter queue binding all the message in single line and how can i segregate it and index into Elasticsearch.

Please find the dead\_letter message below

> `2020-06-26T12:05:04.682Z¦qjava.util.HashMap¦dDATA¦xorg.logstash.ConvertedMap¦cenv¦torg.jruby.RubyStringbpr¦hfacility¦torg.jruby.RubyStringflocal1¦hseverity¦torg.jruby.RubyStringfnotice¦hfilename¦torg.jruby.RubyStringx7cache-sss.log¦kdata_centre¦torg.jruby.RubyStringdWest¦ctag¦torg.jruby.RubyStringkapplication¦dport¦kprogramname¦torg.jruby.RubyStringkapplication¦dhost¦torg.jruby.RubyStringk10.xx.xx.1¦j@timestamp¦vorg.logstash.Timestampx2020-06-26T11:45:31.609Z¦jsysloghost¦torg.jruby.RubyStringlaaaapppddddcc28¦hhostname¦torg.jruby.RubyStringlcaaaapppddddcc28¦ehnnum¦torg.jruby.RubyStringb28¦fprocid¦torg.jruby.RubyStringa-¦kenvironment¦torg.jruby.RubyStringjProduction¦fhnpref¦torg.jruby.RubyStringgcbmrmmr¦gmessage¦torg.jruby.RubyStringx0 To: Sun Aug 09 15:15:35 IST 2020]¦h@version¦torg.jruby.RubyStringa1¦eappid¦torg.jruby.RubyStringhmulesoft¦glogtype¦torg.jruby.RubyStringcapp¦¦¦dMETA¦xorg.logstash.ConvertedMaelasticsearch¦Could not index event to Elasticsearch. status: 400, action: ["index", {:_id=>nil, :_index=>"mulesoft-pr-logstash-2020.06", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x3b0a2b84>], response: {"index"=>{"_index"=>"mulesoft-pr-logstash-2020.06", "_type"=>"doc", "_id"=>"t6eE8HIBQCAYDMTgVruI", "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"number of documents in the index cannot exceed 2147483519"}}}c¦¦¦¦?¦¦`

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [June 30, 2020, 4:45am UTC](https://discuss.elastic.co/t/dead-letter-cannot-write-event-to-dlq-reached-maxqueuesize-of-2147483648/239100/4 "2020-06-30T04:45:00Z")

</div>

Hello Ganesh,

Which version are you on? This looks different than I am used to. What is interesting is the message:

> number of documents in the index cannot exceed 2147483519

This error message is new to me but I guess it has to do with a limited amount of documents a single shard within an index can support. How many primary shards does the index have?

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [June 30, 2020, 8:01am UTC](https://discuss.elastic.co/t/dead-letter-cannot-write-event-to-dlq-reached-maxqueuesize-of-2147483648/239100/5 "2020-06-30T08:01:00Z")

</div>

@Wolfram_Haussig currently we are using 6.4 version and we have 1 primary shards for each index.

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [July 2, 2020, 7:01pm UTC](https://discuss.elastic.co/t/dead-letter-cannot-write-event-to-dlq-reached-maxqueuesize-of-2147483648/239100/6 "2020-07-02T19:01:38Z")

</div>

Do you have any input for this issue @Wolfram_Haussig

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [July 3, 2020, 4:24am UTC](https://discuss.elastic.co/t/dead-letter-cannot-write-event-to-dlq-reached-maxqueuesize-of-2147483648/239100/7 "2020-07-03T04:24:55Z")

</div>

Hello Ganesh,

I think you need to add more shards to your index. As it is not possible to change the number of shards of an existing index you need to create a new one increasing the primary shard count.

Then you could [reindex](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/docs-reindex.html) the old index into the new one and after this migration you can delete the old index.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2020, 4:31am UTC](https://discuss.elastic.co/t/dead-letter-cannot-write-event-to-dlq-reached-maxqueuesize-of-2147483648/239100/8 "2020-07-31T04:31:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
