# Field maxlength?

**URL:** <https://discuss.elastic.co/t/field-maxlength/45357>\
**Category:** Kibana\
**Created:** [March 24, 2016, 2:56pm UTC](https://discuss.elastic.co/t/field-maxlength/45357 "2016-03-24T14:56:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 24, 2016, 2:56pm UTC](https://discuss.elastic.co/t/field-maxlength/45357/1 "2016-03-24T14:56:32Z")

</div>

I have a java log with some entries having stacktraces. I'm using the multiline option in filebeat and a grok filter in logstash with the pattern ending in GREEDYDATA, i.e.:

`SNIP%{GREEDYDATA:logmessage}`

This works fine with logmessage sometimes having up to 100 lines though. In Kibana's Discover tab I see the whole stacktrace but in visualizations they appear empty, as if there was no data in that field. Could this be caused by a maximum field length in Kibana visualizations? I'm using version 4.4.0.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [March 24, 2016, 10:38pm UTC](https://discuss.elastic.co/t/field-maxlength/45357/2 "2016-03-24T22:38:12Z")

</div>

I'm going to try to reproduce your issue but need to create some test data... But let me know if you already figured it out.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [March 24, 2016, 11:23pm UTC](https://discuss.elastic.co/t/field-maxlength/45357/3 "2016-03-24T23:23:25Z")

</div>

Can you show a screenshot of what you see? Do you have the `.raw` field for the long string field?  
In my test I don't (yet) and so I only get the first word of the long string field instead of the whole string.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [March 24, 2016, 11:40pm UTC](https://discuss.elastic.co/t/field-maxlength/45357/4 "2016-03-24T23:40:13Z")

</div>

Once I added the .raw field I can see a very long string (over 4000 characters) in a visualization (data table) (I actually did one more with a string over 8000 characters and it all shows up);

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/c2d5c04d1903b68865831b38b916d7504b9ee6a0.png)

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 29, 2016, 1:08pm UTC](https://discuss.elastic.co/t/field-maxlength/45357/5 "2016-03-29T13:08:31Z")

</div>

Thanks Lee. BTW, I'm speaking with Jay Greenberg about this. Sorry about the crosspost. The only difference I see compared to yours is mine is a Java stacktrace and so typically starts with something like "org.something.something.SomeException: some message. \n\t some other lines". That and one stacktrace is 14000 characters.

---

<div class="post-metadata">

**Author:** ![PhaedrusTheGreek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phaedrusthegreek/32/4884_2.png) [@PhaedrusTheGreek](https://discuss.elastic.co/u/PhaedrusTheGreek)\
**Post date:** [March 29, 2016, 5:11pm UTC](https://discuss.elastic.co/t/field-maxlength/45357/6 "2016-03-29T17:11:27Z")

</div>

There is a [maximum term length under Lucene](https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-above.html).

You can avert this behaviour by using the `ignore-above` setting to ensure you come in under the limit. Something like this should work:

```auto
{
"exception": {
     "mapping": {
        "type": "string",
        "fields": {
           "raw": {
              "ignore_above": 10922,
              "index": "not_analyzed",
              "type": "string"
           }
        }
     }
  }
}

```

From the docs:

> The value for ignore\_above is the character count, but Lucene counts bytes. If you use UTF-8 text with many non-ASCII characters, you may want to set the limit to 32766 / 3 = 10922 since UTF-8 characters may occupy at most 3 bytes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:57pm UTC](https://discuss.elastic.co/t/field-maxlength/45357/7 "2017-07-06T13:57:33Z")

</div>


