# Filebeat setup: error loading index pattern: returned 413 to import file: invalid character ‘\<’ looking for beginning of value

**URL:** <https://discuss.elastic.co/t/filebeat-setup-error-loading-index-pattern-returned-413-to-import-file-invalid-character-looking-for-beginning-of-value/315329>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 28, 2022, 6:56am UTC](https://discuss.elastic.co/t/filebeat-setup-error-loading-index-pattern-returned-413-to-import-file-invalid-character-looking-for-beginning-of-value/315329 "2022-09-28T06:56:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nick95](https://avatars.discourse-cdn.com/v4/letter/n/8e7dd6/32.png) [@Nick95](https://discuss.elastic.co/u/Nick95)\
**Post date:** [September 28, 2022, 6:56am UTC](https://discuss.elastic.co/t/filebeat-setup-error-loading-index-pattern-returned-413-to-import-file-invalid-character-looking-for-beginning-of-value/315329/1 "2022-09-28T06:56:38Z")

</div>

Hi,

I try to run a filebeat on a server. Elastic and Kibana are installed on another server and are pushed on 443 port via a Nginx reverse proxy. Kibana GUI is working on the IP I set up (https with self-generated certificate).

When I run # sudo filebeat setup I get this error:

```auto
Exiting: 1 error: error loading index pattern: returned 413 to import file: invalid character '<' looking for beginning of value. Response: <html>
<head><title>413 Request Entity Too Large</title></head>
<body bgcolor="white">
<center><h1>413 Request Entity Too Large</h1></center>
<hr><center>nginx/1.14.1</center>
</body>
</html>

```

**Filebeat.yml On the filebeat server (only the uncommented lines)**

```auto
# ============================== Filebeat inputs ===============================

filebeat.inputs:

- type: filestream

  id: my-filestream-id

  enabled: false

  paths:

    - /var/log/*.log

# ============================== Filebeat modules ==============================

filebeat.config.modules:

  path: ${path.config}/modules.d/*.yml

  reload.enabled: false

# ================================== Outputs ===================================

# ---------------------------- Elasticsearch Output ----------------------------

output.elasticsearch:

  hosts: ["<IP-ES-KIBANA>:443/es/"]

  ssl.certificate: "/ca/ca.crt"

  ssl.key: "/ca/ca.key"

  ssl.verification_mode: "none"

# ================================= Processors =================================

processors:

  - add_host_metadata:

      when.not.contains.tags: forwarded

  - add_cloud_metadata: ~

  - add_docker_metadata: ~

  - add_kubernetes_metadata: ~

```

**Nginx conf on the Elastic/Kibana server**

```auto
server {

  listen 443 ssl; 

  server_name <IP-ES-KIBANA>;

 

  ssl on;

  ssl_certificate /ca/ca.crt;

  ssl_certificate_key /ca/ca.key;

 

  location /kibana/ {

    proxy_pass http://localhost:5601/;

      }

 

  location /es/ {

    proxy_pass http://localhost:9200/;

    #proxy_read_timeout 90;

  }

}

```

Version filebeat: 8.2.2 / Version Elastic search: 8.2.2  
Can someone help to figure it out what it is?

Thanks in advance …

---

<div class="post-metadata">

**Author:** ![Nick95](https://avatars.discourse-cdn.com/v4/letter/n/8e7dd6/32.png) [@Nick95](https://discuss.elastic.co/u/Nick95)\
**Post date:** [October 6, 2022, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-setup-error-loading-index-pattern-returned-413-to-import-file-invalid-character-looking-for-beginning-of-value/315329/2 "2022-10-06T13:50:49Z")

</div>

I solve this issue by adding :  
client\_max\_body\_size 100M;  
in the nginx.conf file

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2022, 3:51pm UTC](https://discuss.elastic.co/t/filebeat-setup-error-loading-index-pattern-returned-413-to-import-file-invalid-character-looking-for-beginning-of-value/315329/3 "2022-11-03T15:51:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
