# Getting Maximum Bytes length Exception in Logstash Indexer

**URL:** <https://discuss.elastic.co/t/getting-maximum-bytes-length-exception-in-logstash-indexer/69011>\
**Category:** Logstash\
**Created:** [December 14, 2016, 12:05pm UTC](https://discuss.elastic.co/t/getting-maximum-bytes-length-exception-in-logstash-indexer/69011 "2016-12-14T12:05:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![NITIN-BHAISARE](https://avatars.discourse-cdn.com/v4/letter/n/c89c15/32.png) [@NITIN-BHAISARE](https://discuss.elastic.co/u/NITIN-BHAISARE)\
**Post date:** [December 14, 2016, 12:05pm UTC](https://discuss.elastic.co/t/getting-maximum-bytes-length-exception-in-logstash-indexer/69011/1 "2016-12-14T12:05:52Z")

</div>

Hey,  
I am continuously getting this error on the logstash indexer, I don't know how to resolve this. please, can somebody please help me out how to get this resolved. I have 3Millions messages waiting in the RabbitMQ waiting.

"reason"=\>"Document contains at least one immense term in field="message" (whose UTF8 encoding is longer than the max length 32766), all of which were skipped. Please correct the analyzer to not produce such terms. The prefix of the first immense term is: '[77, 101, 115, 115, 97, 103, 101, 32, 98, 111, 100, 121, 58, 32, 123, 34, 109, 105, 109, 101, 95, 116, 121, 112, 101, 34, 58, 34, 97, 112]...', original message: bytes can be at most 32766 in length; got 93268", "caused\_by"=\>{"type"=\>"max\_bytes\_length\_exceeded\_exception", "reason"=\>"max\_bytes\_length\_exceeded\_exception: bytes can be at most 32766 in length; got 93268"}}}}, :level=\>:warn}

Thanks

---

<div class="post-metadata">

**Author:** ![aeva\_assured](https://avatars.discourse-cdn.com/v4/letter/a/35a633/32.png) [@aeva\_assured](https://discuss.elastic.co/u/aeva_assured)\
**Post date:** [December 14, 2016, 2:17pm UTC](https://discuss.elastic.co/t/getting-maximum-bytes-length-exception-in-logstash-indexer/69011/2 "2016-12-14T14:17:15Z")

</div>

> [@NITIN-BHAISARE](#):
>
> "reason"=\>"max\_bytes\_length\_exceeded\_exception: bytes can be at most 32766 in length; got 93268"}}}},

Sounds like you have something that exceeds 32,766 bytes. Change the value from Bytes to Float, that should give much more room for larger numbers. Then you can set it back to bytes when it gets to elasticsearch.

---

<div class="post-metadata">

**Author:** ![NITIN-BHAISARE](https://avatars.discourse-cdn.com/v4/letter/n/c89c15/32.png) [@NITIN-BHAISARE](https://discuss.elastic.co/u/NITIN-BHAISARE)\
**Post date:** [December 15, 2016, 7:17am UTC](https://discuss.elastic.co/t/getting-maximum-bytes-length-exception-in-logstash-indexer/69011/3 "2016-12-15T07:17:40Z")

</div>

> Change the value from Bytes to Float, that should give much more room for larger numbers. Then you can set it back to bytes when it gets to elasticsearch.

how to do this? I don't know how to do it.

Thanks

---

<div class="post-metadata">

**Author:** ![aeva\_assured](https://avatars.discourse-cdn.com/v4/letter/a/35a633/32.png) [@aeva\_assured](https://discuss.elastic.co/u/aeva_assured)\
**Post date:** [December 15, 2016, 2:18pm UTC](https://discuss.elastic.co/t/getting-maximum-bytes-length-exception-in-logstash-indexer/69011/4 "2016-12-15T14:18:58Z")

</div>

It would be helpful if you posted your filter code. The easiest way would be to add it into the syntax.

For example, if you are collecting into a filter like this:  
  
%{NUMBER:bytes}

You can change it to:  
  
%{BASE16FLOAT:bytes}

Here is a list of the default grok patterns.  
[Grok Patterns](https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/grok-patterns)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2017, 2:19pm UTC](https://discuss.elastic.co/t/getting-maximum-bytes-length-exception-in-logstash-indexer/69011/5 "2017-01-12T14:19:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
