# Discover fails with "content length bigger than max allowed string" on index with large text field

**URL:** <https://discuss.elastic.co/t/discover-fails-with-content-length-bigger-than-max-allowed-string-on-index-with-large-text-field/388911>\
**Category:** Elasticsearch\
**Created:** [July 30, 2026, 4:28pm UTC](https://discuss.elastic.co/t/discover-fails-with-content-length-bigger-than-max-allowed-string-on-index-with-large-text-field/388911 "2026-07-30T16:28:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mouly\_Infy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mouly_infy/32/147978_2.png) [@Mouly\_Infy](https://discuss.elastic.co/u/Mouly_Infy)\
**Post date:** [July 30, 2026, 4:28pm UTC](https://discuss.elastic.co/t/discover-fails-with-content-length-bigger-than-max-allowed-string-on-index-with-large-text-field/388911/1 "2026-07-30T16:28:50Z")

</div>

Hello Connections,

We're facing an issue when trying to retrieve documents in Discover, and wanted to get community input on the best long-term fix.

**Environment:**

- Elastic Stack version: [8.19.3]
- Deployment: self-managed on EC2
- Ingestion path: Filebeat → Logstash → Elasticsearch

**The error:**

When loading Discover against one of our production data views (`index-*` indices), we get:

 ![942f5b_image](https://us1.discourse-cdn.com/elastic/original/3X/3/e/3e87c287f4efc5282fb48c4f5b6e012e61be27e4.png)  
**Root cause we've identified:**

One field in our documents (a payload/raw\_payload text field, is extremely large on a subset of documents — we found individual documents as large as ~23MB in a single index, versus ~2KB for typical documents in the same index. When Discover's default query returns full \_source for a batch of matched hits, the aggregate response for even a short time window (minutes, not hours) exceeds ~512MB and the browser fails to parse it.

We need to have the document and where the payload is in event.original

Any suggestion to fix

Thanks in advance

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [July 30, 2026, 5:23pm UTC](https://discuss.elastic.co/t/discover-fails-with-content-length-bigger-than-max-allowed-string-on-index-with-large-text-field/388911/2 "2026-07-30T17:23:27Z")

</div>

welcome to the forum @Mouly_Infy

This has been asked directly or indirectly a couplee of times, e.g. [here](https://discuss.elastic.co/t/context-length-is-bigger-than-maximum-allowed-string/356985)

See this [github](https://github.com/elastic/kibana/issues/173346) thread too for some ideas.

You need be careful here too as other clients (not just Kibana/Discover) can hit issues with large HTTP payloads. I dont know your use case and what you are specifically trying to do, but it's unlikely there is much value in "seeing" a 23 MB document within Kibana.
