# How to get and filter transactions based on response header Content-Length

**URL:** <https://discuss.elastic.co/t/how-to-get-and-filter-transactions-based-on-response-header-content-length/353894>\
**Category:** APM\
**Tags:** java, server\
**Created:** [February 22, 2024, 2:40pm UTC](https://discuss.elastic.co/t/how-to-get-and-filter-transactions-based-on-response-header-content-length/353894 "2024-02-22T14:40:12Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bukajsytlos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bukajsytlos/32/132007_2.png) [@bukajsytlos](https://discuss.elastic.co/u/bukajsytlos)\
**Post date:** [February 22, 2024, 2:40pm UTC](https://discuss.elastic.co/t/how-to-get-and-filter-transactions-based-on-response-header-content-length/353894/1 "2024-02-22T14:40:12Z")

</div>

Essentially the topic.  
We would like to search for responses based on size of the responses.  
From what I understand, this header is not logged by default. Even if they would we would have to add them to index like [Configure Elasticsearch index template loading | APM Server Reference [7.15] | Elastic](https://www.elastic.co/guide/en/apm/server/7.15/configuration-template.html), right?  
Thanks

---

<div class="post-metadata">

**Author:** ![Jonas\_Kunz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonas_kunz/32/110740_2.png) [@Jonas\_Kunz](https://discuss.elastic.co/u/Jonas_Kunz)\
**Post date:** [February 22, 2024, 3:09pm UTC](https://discuss.elastic.co/t/how-to-get-and-filter-transactions-based-on-response-header-content-length/353894/2 "2024-02-22T15:09:26Z")

</div>

The apm java agent should [capture headers by default](https://www.elastic.co/guide/en/apm/agent/java/current/config-core.html#config-capture-headers).

What HTTP library (client/server) of which you want to see the headers are you using?

---

<div class="post-metadata">

**Author:** ![bukajsytlos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bukajsytlos/32/132007_2.png) [@bukajsytlos](https://discuss.elastic.co/u/bukajsytlos)\
**Post date:** [February 23, 2024, 9:04am UTC](https://discuss.elastic.co/t/how-to-get-and-filter-transactions-based-on-response-header-content-length/353894/3 "2024-02-23T09:04:47Z")

</div>

Yes headers are captured, but not this one. This is what we see

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/d/9d273246f4b57565437f835cbabadb7c0c08dd1d.png)  
we are using spring mvc and camel over spring.

---

<div class="post-metadata">

**Author:** ![Jonas\_Kunz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonas_kunz/32/110740_2.png) [@Jonas\_Kunz](https://discuss.elastic.co/u/Jonas_Kunz)\
**Post date:** [February 23, 2024, 9:25am UTC](https://discuss.elastic.co/t/how-to-get-and-filter-transactions-based-on-response-header-content-length/353894/4 "2024-02-23T09:25:10Z")

</div>

The headers you provided show that `Transfer-Encoding` is `chunked`, meaning that your request doesn't have a `Content-Length` header: the data is streamed and the total size is not known at the point in time the headers are sent.

I think the only option you have is to modify your code and add the content length to your transaction as a label. I'd recommend using the [OpenTelemetry API](https://www.elastic.co/guide/en/apm/agent/java/current/opentelemetry-bridge.html#otel-set-attribute).

---

<div class="post-metadata">

**Author:** ![bukajsytlos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bukajsytlos/32/132007_2.png) [@bukajsytlos](https://discuss.elastic.co/u/bukajsytlos)\
**Post date:** [February 23, 2024, 12:24pm UTC](https://discuss.elastic.co/t/how-to-get-and-filter-transactions-based-on-response-header-content-length/353894/5 "2024-02-23T12:24:08Z")

</div>

oh. thanks

---

<div class="post-metadata">

**Author:** ![bukajsytlos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bukajsytlos/32/132007_2.png) [@bukajsytlos](https://discuss.elastic.co/u/bukajsytlos)\
**Post date:** [February 23, 2024, 2:52pm UTC](https://discuss.elastic.co/t/how-to-get-and-filter-transactions-based-on-response-header-content-length/353894/6 "2024-02-23T14:52:49Z")

</div>

OK the "issue" seems to be that json converter is streaming the response. I am curious, if it would be possible for agent to hook and wrap servlet output stream, that would count bytes sent.  
IMHO having information about the size of request/response is about the same as having info about the duration.

---

<div class="post-metadata">

**Author:** ![Jonas\_Kunz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonas_kunz/32/110740_2.png) [@Jonas\_Kunz](https://discuss.elastic.co/u/Jonas_Kunz)\
**Post date:** [March 5, 2024, 8:05am UTC](https://discuss.elastic.co/t/how-to-get-and-filter-transactions-based-on-response-header-content-length/353894/7 "2024-03-05T08:05:41Z")

</div>

> it would be possible agent to hook and wrap servlet output stream

It definitiely is possible, however it is a dangerous thing to do: There are many application out there, which rely on having a specific subtype of `OutputStream` and cast them accordingly. If the agent now wraps the output stream, this would suddenly break the application.

This is also one of the main reasons why we don't support capturing request and response content for the server requests being handled by the application.

If you want to, you could however try to implement this using a [custom plugin](https://www.elastic.co/guide/en/apm/agent/java/current/plugin-api.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2024, 8:05am UTC](https://discuss.elastic.co/t/how-to-get-and-filter-transactions-based-on-response-header-content-length/353894/8 "2024-04-02T08:05:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
