# Elastic-agent is triggering HTTP 413 (entity too large) errors

**URL:** <https://discuss.elastic.co/t/elastic-agent-is-triggering-http-413-entity-too-large-errors/341932>\
**Category:** Elastic Agent\
**Tags:** filebeat\
**Created:** [August 30, 2023, 12:42am UTC](https://discuss.elastic.co/t/elastic-agent-is-triggering-http-413-entity-too-large-errors/341932 "2023-08-30T00:42:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig\_Rodrigues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_rodrigues/32/121875_2.png) [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Post date:** [August 30, 2023, 12:42am UTC](https://discuss.elastic.co/t/elastic-agent-is-triggering-http-413-entity-too-large-errors/341932/1 "2023-08-30T00:42:49Z")

</div>

I have an elastic agent:

```auto
elastic-agent version

```

```auto
Binary: 8.9.0 (build: dc443bc2427920a26141b05f9c07a52191881af5 at 2023-07-19 20:55:16 +0000 UTC)
Daemon: 8.9.0 (build: dc443bc2427920a26141b05f9c07a52191881af5 at 2023-07-19 20:55:16 +0000 UTC)

```

```auto
elastic-agent status

```

```auto
┌─ fleet
│ └─ status: (HEALTHY) Connected
└─ elastic-agent
   └─ status: (HEALTHY) Running

```

If I do:

```auto
elastic-agent logs | jq

```

I am seeing some errors like:

```json
{
  "log.level": "error",
  "@timestamp": "2023-08-29T22:51:52.377Z",
  "message": "failed to publish events: Post \"https://myelasticsearch.example:443/_bulk\": write tcp [redacted]:33430->[redacted]:443: write: broken pipe",
  "component": {
    "binary": "filebeat",
    "dataset": "elastic_agent.filebeat",
    "id": "filestream-default",
    "type": "filestream"
  },
  "log": {
    "source": "filestream-default"
  },
  "log.origin": {
    "file.line": 174,
    "file.name": "pipeline/client_worker.go"
  },
  "service.name": "filebeat",
  "ecs.version": "1.6.0",
  "log.logger": "publisher_pipeline_output"
}
{
  "log.level": "error",
  "@timestamp": "2023-08-29T22:51:53.079Z",
  "message": "failed to perform any bulk index operations: Post \"https://myelasticsearch.example:443/_bulk\": write tcp [redacted]:33436->[redacted]:443: write: connection reset by peer",
  "component": {
    "binary": "filebeat",
    "dataset": "elastic_agent.filebeat",
    "id": "filestream-default",
    "type": "filestream"
  },
  "log": {
    "source": "filestream-default"
  },
  "log.origin": {
    "file.line": 258,
    "file.name": "elasticsearch/client.go"
  },
  "service.name": "filebeat",
  "ecs.version": "1.6.0",
  "log.logger": "elasticsearch"
}

```

If I use a protocol debugger, I see that HTTP 413 Entity Too Large errors are being thrown by the backend.

My Elasticsearch server is configured with `"http.max_content_length": "100mb"`, (as seen from the `_cluster/settings` API).

How can I tell how large the payload that elastic-agent is sending to the server?

How can I throttle the size of the payload that elastic-agent is sending to the server?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2023, 12:43am UTC](https://discuss.elastic.co/t/elastic-agent-is-triggering-http-413-entity-too-large-errors/341932/2 "2023-09-27T00:43:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
