# Getting error 'Payload Too Large' in Kibana UI

**URL:** <https://discuss.elastic.co/t/getting-error-payload-too-large-in-kibana-ui/378246>\
**Category:** Kibana\
**Created:** [May 16, 2025, 6:21pm UTC](https://discuss.elastic.co/t/getting-error-payload-too-large-in-kibana-ui/378246 "2025-05-16T18:21:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Natalia\_Mellino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/natalia_mellino/32/137449_2.png) [@Natalia\_Mellino](https://discuss.elastic.co/u/Natalia_Mellino)\
**Post date:** [May 16, 2025, 6:21pm UTC](https://discuss.elastic.co/t/getting-error-payload-too-large-in-kibana-ui/378246/1 "2025-05-16T18:21:12Z")

</div>

Hello! We are currently running the ELK on 7.17.26 version along with ReadonlyREST plugin in both Kibana an Elasticsearch in order to use Keycloak authentication in Kibana. This past weeks some users were experiencing this error in the Kibana UI when they log in:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/6/06708d835f08dc5b0087d51f1a1e24df9fcff97e.png)

We've had this issue before and we know it's because of the amount of permissions that are attatched to some users when they log in. For now the workaround is to make the users remove some unused permissions and they are able to enter Kibana again. We recently implemented some filtering of unnecessary permissions in Keycloak side to help with this issue, but this is not a permanent solution because the amount of permissions might keep growing (we handle a big amount of logs and access must be restricted so permissions are needed).

We already asked about this in the ReadonlyREST forum and they assured that this error screen does not come from their side. We also checked our NGINX running in our Kibana server and it doesn't seem to be the problem either. Our only thing left to confirm is if this error comes from Kibana because we have no other place to look for.

If you by any chance can help with this we'd aprecciate it since it's only a matter of time before we face this issue again. Let me know if I can provide any other information.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [May 16, 2025, 9:23pm UTC](https://discuss.elastic.co/t/getting-error-payload-too-large-in-kibana-ui/378246/2 "2025-05-16T21:23:57Z")

</div>

Hi @Natalia_Mellino,

I assume you are using your own on-prem install? Have you tried increasing the [`server.maxPayload` setting](https://www.elastic.co/guide/en/kibana/7.17/settings.html#server-maxPayload).

I would still be careful not to set it too high for performance reasons, but you could see if that helps.

Let us know!

---

<div class="post-metadata">

**Author:** ![Natalia\_Mellino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/natalia_mellino/32/137449_2.png) [@Natalia\_Mellino](https://discuss.elastic.co/u/Natalia_Mellino)\
**Post date:** [May 19, 2025, 12:23pm UTC](https://discuss.elastic.co/t/getting-error-payload-too-large-in-kibana-ui/378246/3 "2025-05-19T12:23:42Z")

</div>

Hi! Thank you for your help. We saw that setting in the documentation and we were not sure about it, because we couldn't test it properly in that moment, so we went with the permission filtering instead. We have a test environment now where we are able to replicate this issue and I already asked my team to try this so I'll get back here when we do.

About the error itself, can you confirm if this message error comes from Kibana? We were investigating a lot trying to find out where does it come from (to understand better) and we found nothing, it does not seem to come from Elasticsearch, ReadonlyREST, Keycloak nor NGINX from what we saw.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [May 19, 2025, 1:15pm UTC](https://discuss.elastic.co/t/getting-error-payload-too-large-in-kibana-ui/378246/4 "2025-05-19T13:15:57Z")

</div>

I do see related issues with the same error in Kibana, which is why I'm guessing it's coming from Kibana. Have you checked the Kibana logs to see if the error is in there?

---

<div class="post-metadata">

**Author:** ![Natalia\_Mellino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/natalia_mellino/32/137449_2.png) [@Natalia\_Mellino](https://discuss.elastic.co/u/Natalia_Mellino)\
**Post date:** [May 19, 2025, 1:20pm UTC](https://discuss.elastic.co/t/getting-error-payload-too-large-in-kibana-ui/378246/5 "2025-05-19T13:20:35Z")

</div>

Yes, we've checked but nothing specific appears in the logs when an user fails to login with this message, no errors, no warnings, anything. (Logging is enabled on 'INFO' level).
