# ELK error

**URL:** <https://discuss.elastic.co/t/elk-error/110863>\
**Category:** Kibana\
**Created:** [December 8, 2017, 2:47pm UTC](https://discuss.elastic.co/t/elk-error/110863 "2017-12-08T14:47:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![SunGirl](https://avatars.discourse-cdn.com/v4/letter/s/eb8c5e/32.png) [@SunGirl](https://discuss.elastic.co/u/SunGirl)\
**Post date:** [December 8, 2017, 2:47pm UTC](https://discuss.elastic.co/t/elk-error/110863/1 "2017-12-08T14:47:00Z")

</div>

Hi! I added a new log file to logstash (the following lines to logstash.conf 🙂

# Input section

input {  
...

# VirusTotal

file {  
path =\> ["/data/vt/log.json"]  
codec =\> json  
type =\> "VirusTotal"  
}  
}

# Filter Section

filter {  
...

# VirusTotal

if [type] == "VirusTotal" {  
date {  
match =\> ["timestamp", "ISO8601"]  
}  
}  
...

if [type] == ... or [type] == "VirusTotal" {  
mutate {  
add\_field =\> {  
"ip\_ext" =\> "{MY\_EXTIP}" "ip\_int" =\> "{MY\_INTIP}"  
"hostname" =\> "${MY\_HOSTNAME}"  
}  
}  
}

# Output section

output {  
elasticsearch {  
hosts =\> ["elasticsearch:9200"]  
}

Test of logsatsh.conf says everything is OK  
But when I go to kibana Index Patterns -\> Refresh field list fileds from my new log file appear in the list, but kibana shows error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/2/b24b0bf58725ae0b71cbdaa52dd7d686ae107ff1.png)

I don`t know how to solve this problem. Thank you in advance for your help!

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [December 8, 2017, 5:30pm UTC](https://discuss.elastic.co/t/elk-error/110863/2 "2017-12-08T17:30:40Z")

</div>

Hi there, this sounds related to [Kibana 5.1.2/ES 5.1.2 - Index patterns with more than 1000 fields](https://discuss.elastic.co/t/kibana-5-1-2-es-5-1-2-index-patterns-with-more-than-1000-fields/72567). From that post:

> The 413 (PAYLOAD TOO LARGE) response is actually most likely coming from Elasticsearch. Kibana is just surfacing the error it gets back.
> 
> It happens as part of a request Kibana is making to it, so it would be useful to see what that request looks like. If you open your browser's debugger, you can check the request in the network request. That might indicate why that request is so large... most likely it's related to the field count, but I couldn't tell you offhand why field count would be making a request to large.

Could you check the network requests that get logged when you refresh the field list and tell me what you see there?

And could you tell me which version of the Elastic Stack you're using?

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![SunGirl](https://avatars.discourse-cdn.com/v4/letter/s/eb8c5e/32.png) [@SunGirl](https://discuss.elastic.co/u/SunGirl)\
**Post date:** [December 11, 2017, 8:08am UTC](https://discuss.elastic.co/t/elk-error/110863/4 "2017-12-11T08:08:16Z")

</div>

I`m sorry! It really shows the error "413 Request Entity Too Large". The problem is solved and it wasn`t related at all to elk! Thank you very much for your help!

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [December 11, 2017, 7:29pm UTC](https://discuss.elastic.co/t/elk-error/110863/5 "2017-12-11T19:29:32Z")

</div>

Ah, glad you were able to figure it out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 7:31pm UTC](https://discuss.elastic.co/t/elk-error/110863/6 "2018-01-08T19:31:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
