# Filebeat sends incomplete message both in logstash and elasticsearch

**URL:** <https://discuss.elastic.co/t/filebeat-sends-incomplete-message-both-in-logstash-and-elasticsearch/114007>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 4, 2018, 3:36am UTC](https://discuss.elastic.co/t/filebeat-sends-incomplete-message-both-in-logstash-and-elasticsearch/114007 "2018-01-04T03:36:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![inhinyera16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inhinyera16/32/61625_2.png) [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Post date:** [January 4, 2018, 3:36am UTC](https://discuss.elastic.co/t/filebeat-sends-incomplete-message-both-in-logstash-and-elasticsearch/114007/1 "2018-01-04T03:36:58Z")

</div>

We've noticed that our message seems incomplete in filebeat/logstash. Btw, the message field is our xml payload, and we need to store this for searching. When we stdout in filebeat, the message is somewhat cut, i wonder if field has maximum number of characters that was cut when it reaches the maximum? Kindly help. TIA

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 4, 2018, 1:27pm UTC](https://discuss.elastic.co/t/filebeat-sends-incomplete-message-both-in-logstash-and-elasticsearch/114007/2 "2018-01-04T13:27:02Z")

</div>

Are you using multiline?

By default multiline only publishes the first 500 lines.  
By default an event is cut short at 10MB.

Check docs or reference configuration for `max_bytes` and `max_lines` settings.

---

<div class="post-metadata">

**Author:** ![inhinyera16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inhinyera16/32/61625_2.png) [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Post date:** [January 5, 2018, 5:32am UTC](https://discuss.elastic.co/t/filebeat-sends-incomplete-message-both-in-logstash-and-elasticsearch/114007/3 "2018-01-05T05:32:46Z")

</div>

yes, we do use multiline. Where is this max\_bytes and max\_lines configured? In filebeat yml?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 5, 2018, 11:57am UTC](https://discuss.elastic.co/t/filebeat-sends-incomplete-message-both-in-logstash-and-elasticsearch/114007/4 "2018-01-05T11:57:32Z")

</div>

these are per prospector settings.

`max_bytes` for limiting event size within the prospector.

`multiline.max_lines` to limit max lines.

See [Prospector Configurations Docs](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#_configuration_options).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2018, 11:57am UTC](https://discuss.elastic.co/t/filebeat-sends-incomplete-message-both-in-logstash-and-elasticsearch/114007/5 "2018-02-02T11:57:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
