# How to increase byte size in processing in logstash?

**URL:** <https://discuss.elastic.co/t/how-to-increase-byte-size-in-processing-in-logstash/71327>\
**Category:** Logstash\
**Created:** [January 12, 2017, 7:24am UTC](https://discuss.elastic.co/t/how-to-increase-byte-size-in-processing-in-logstash/71327 "2017-01-12T07:24:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shweta](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Shweta](https://discuss.elastic.co/u/Shweta)\
**Post date:** [January 12, 2017, 7:24am UTC](https://discuss.elastic.co/t/how-to-increase-byte-size-in-processing-in-logstash/71327/1 "2017-01-12T07:24:27Z")

</div>

Hi,

While filtering logs in logstash we came across an error which states reason as:

"reason"=\>"max\_bytes\_length\_exceeded\_exception: bytes can be at most 32766 in length; got 56665"}}}}

We cannot tokenize our message field. Please let us know if there is any way to get rid of this limit, so that it will be able to filter mesages greater than 32kb.

Thanks,  
Shweta

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [January 12, 2017, 11:18am UTC](https://discuss.elastic.co/t/how-to-increase-byte-size-in-processing-in-logstash/71327/2 "2017-01-12T11:18:10Z")

</div>

which filter is causing this? can you post your config? and the whole error log line?

---

<div class="post-metadata">

**Author:** ![Shweta](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Shweta](https://discuss.elastic.co/u/Shweta)\
**Post date:** [January 12, 2017, 11:52am UTC](https://discuss.elastic.co/t/how-to-increase-byte-size-in-processing-in-logstash/71327/3 "2017-01-12T11:52:37Z")

</div>

I am getting a big long error consisting of complete parsed log event with all details and below is the part which puts more light on the problem. Hope this helps you

> "reason"=\>"Document contains at least one immense term in field="message" (whose UTF8 encoding is longer than the max length 32766), all of which were skipped. Please correct the analyzer to not produce such terms. The prefix of the first immense term is: '[10, 10, 42, 42, 42, 42, 42, 42, 32, 99, 104, 97, 105, 110, 32, 42, 42, 42, 42, 42, 42, 10, 78, 97, 109, 101, 58, 32, 67, 77]...', original message: bytes can be at most 32766 in length; got 52634", "caused\_by"=\>{"type"=\>"max\_bytes\_length\_exceeded\_exception", "reason"=\>"max\_bytes\_length\_exceeded\_exception: bytes can be at most 32766 in length; got 52634"}}}}, :level=\>:warn}

how can we increase 32766 limit for a single field ? or is there any workaround for such type of an issues??

Thanks  
Shweta

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [January 12, 2017, 11:57am UTC](https://discuss.elastic.co/t/how-to-increase-byte-size-in-processing-in-logstash/71327/4 "2017-01-12T11:57:09Z")

</div>

This is a characteristic/protection on the elasticsearch side, for more information you can see a similar discuss topic: [UTF8 encoding is longer than the max length 32766](https://discuss.elastic.co/t/utf8-encoding-is-longer-than-the-max-length-32766/816)

---

<div class="post-metadata">

**Author:** ![Shweta](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Shweta](https://discuss.elastic.co/u/Shweta)\
**Post date:** [January 12, 2017, 12:00pm UTC](https://discuss.elastic.co/t/how-to-increase-byte-size-in-processing-in-logstash/71327/5 "2017-01-12T12:00:57Z")

</div>

"index":no is the option we need to provide in template. But we are not sure about its syntax and where exactly to put it. Here is our template:

> {  
> "order": 0,  
> "template": "delivery-app-_",  
> "settings": {  
> "index": {  
> "refresh\_interval": "5s"  
> }  
> },  
> "mappings": {  
> "default": {  
> "dynamic\_templates": [  
> {  
> "template1": {  
> "mapping": {  
> "ignore\_above": 1024,  
> "index": "not\_analyzed",  
> "type": "{dynamic\_type}",  
> "doc\_values": true  
> },  
> "match": "_"  
> }  
> }  
> ],  
> "\_all": {  
> "norms": {  
> "enabled": false  
> },  
> "enabled": true  
> },  
> "properties": {  
> "severity": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "offset": {  
> "type": "long",  
> "doc\_values": "true"  
> },  
> "reportid": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "tmh\_report": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "query": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "reportversion": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "emailid": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "source": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "thread": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "message": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "type": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "filter": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "profile\_name": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "@timestamp": {  
> "type": "date"  
> },  
> "profileid": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "name": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "publish\_date": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "status": {  
> "index": "not\_analyzed",  
> "type": "string"  
> },  
> "timestamp": {  
> "index": "not\_analyzed",  
> "type": "string"  
> }  
> }  
> }  
> },  
> "aliases": {}  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2017, 12:00pm UTC](https://discuss.elastic.co/t/how-to-increase-byte-size-in-processing-in-logstash/71327/6 "2017-02-09T12:00:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
