# Handling failures in ES output plugin

**URL:** https://discuss.elastic.co/t/handling-failures-in-es-output-plugin/155209
**Category:** Logstash
**Created:** [November 2, 2018, 4:49pm UTC](https://discuss.elastic.co/t/handling-failures-in-es-output-plugin/155209 "2018-11-02T16:49:04Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![niks1](https://avatars.discourse-cdn.com/v4/letter/n/dfb087/32.png) [@niks1](https://discuss.elastic.co/u/niks1)
#### Post date: [November 2, 2018, 4:49pm UTC](https://discuss.elastic.co/t/handling-failures-in-es-output-plugin/155209/1 "2018-11-02T16:49:04Z")

</div>

I get this message  
[2018-10-30T18:53:51,945][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"sunshine-txlog-2018.10.30", :\_type=\>"folder", :\_routing=\>nil}, #\<LogStash::Event:0x4056f86f\>], :response=\>{"index"=\>{"\_index"=\>"sunshine-txlog-2018.10.30", "\_type"=\>"folder", "\_id"=\>"AWbGUyyOzlZ3V1ugVeYw", "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Limit of total fields [1000] in index [sunshine-txlog-2018.10.30] has been exceeded"}}}}.

I am pretty new to logstash and ES so was wondering if there is a way to create a metric to see how many unique fields are being send to ES at a time also i think there are fields with bad key are getting through the ES (Is there way to catch it and put it in separate index).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 30, 2018, 4:49pm UTC](https://discuss.elastic.co/t/handling-failures-in-es-output-plugin/155209/2 "2018-11-30T16:49:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
