# How to increase max message size?

**URL:** <https://discuss.elastic.co/t/how-to-increase-max-message-size/43165>\
**Category:** Logstash\
**Created:** [March 1, 2016, 10:01pm UTC](https://discuss.elastic.co/t/how-to-increase-max-message-size/43165 "2016-03-01T22:01:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Junyan](https://avatars.discourse-cdn.com/v4/letter/j/a88e57/32.png) [@Junyan](https://discuss.elastic.co/u/Junyan)\
**Post date:** [March 1, 2016, 10:01pm UTC](https://discuss.elastic.co/t/how-to-increase-max-message-size/43165/1 "2016-03-01T22:01:20Z")

</div>

I am using below logstash.conf. I am using all default settings. The max size of http requests that can be processed correctly is around 130 kb. If the request is larger than 130kb, LogStash does not output to stdout, and does not return an http response.

How to increase the message size that can be processed?

input {  
http {  
port =\> 5544  
codec =\> "json"  
}  
}  
filter {  
ruby {  
code =\> "event['@metadata']['computed\_id'] = event['[LogMessage][Header][MessageId]']"  
}  
date {  
match =\> ["[LogMessage][Header][CreatedDateTime]", "ISO8601" ]  
}  
mutate {  
remove\_field =\> ["host", "headers"]  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "\<applog-{now/d}\>"  
document\_id =\> "%{[@metadata][computed\_id]}"  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 1, 2016, 11:40pm UTC](https://discuss.elastic.co/t/how-to-increase-max-message-size/43165/2 "2016-03-01T23:40:38Z")

</div>

Can you try running in debug to see what happens?

---

<div class="post-metadata">

**Author:** ![Junyan](https://avatars.discourse-cdn.com/v4/letter/j/a88e57/32.png) [@Junyan](https://discuss.elastic.co/u/Junyan)\
**Post date:** [March 2, 2016, 3:35pm UTC](https://discuss.elastic.co/t/how-to-increase-max-message-size/43165/3 "2016-03-02T15:35:41Z")

</div>

I sent a small message at 09:21:47, and I see below entries in LogStash logs. I sent a big message at 09:23:04, and there is nothing in the logs, only "Flushing buffer at interval".

{:timestamp=\>"2016-03-02T09:21:47.740000-0600", :message=\>"Flushing buffer at interval", :instance=\>"#\<LogStash::Outputs::ElasticSearch::Buffer:0x48de003c @operations\_mutex=#Mutex:0x4619e757, @max\_size=500, @operations\_lock=#\<Java::JavaUtilConcurrentLocks::Re

{:timestamp=\>"2016-03-02T09:21:47.795000-0600", :message=\>"Flushing buffer at interval", :instance=\>"#\<LogStash::Outputs::ElasticSearch::Buffer:0x225c556a @operations\_mutex=#Mutex:0x2c9bbf51, @max\_size=500, @operations\_lock=#\<Java::JavaUtilConcurrentLocks::Re

{:timestamp=\>"2016-03-02T09:21:47.795000-0600", :message=\>"Flushing buffer at interval", :instance=\>"#\<LogStash::Outputs::ElasticSearch::Buffer:0xc6c93c1 @operations\_mutex=#Mutex:0x2ab6c3c, @max\_size=500, @operations\_lock=#\<Java::JavaUtilConcurrentLocks::Reen

{:timestamp=\>"2016-03-02T09:21:47.836000-0600", :message=\>"filter received", :event=\>{"LogMessage"=\>{"Header"=\>{"Source"=\>"BPM", "CreatedDateTime"=\>"2016-03-01T19:03:31.032Z", "MessageType"=\>"Event", "MessageName"=\>"CustomerCaseGraphDataService", "MessageVersio

{:timestamp=\>"2016-03-02T09:21:47.841000-0600", :message=\>"Date filter: received event", :type=\>nil, :level=\>:debug, :file=\>"/logstash-2.2.2/vendor/bundle/jruby/1.9/gems/logstash-filter-date-2.1.2/lib/logstash/filters/date.rb", :line=\>"229", :method=\>"filter"}

{:timestamp=\>"2016-03-02T09:21:47.842000-0600", :message=\>"Date filter looking for field", :type=\>nil, :field=\>"[LogMessage][Header][CreatedDateTime]", :level=\>:debug, :file=\>"/logstash-2.2.2/vendor/bundle/jruby/1.9/gems/logstash-filter-date-2.1.2/lib/logstash/filters/date.rb", :line=\>"232", :method=\>"filter"}

{:timestamp=\>"2016-03-01T19:03:31.032Z", :message=\>"Date parsing done", :value=\>"2016-03-01T19:03:31.032Z", :level=\>:debug, :file=\>"/logstash-2.2.2/vendor/bundle/jruby/1.9/gems/logstash-filter-date-2.1.2/lib/logstash/filters/date.rb", :line=\>"266", :method=\>"filter"}

{:timestamp=\>"2016-03-02T09:21:47.844000-0600", :message=\>"filters/LogStash::Filters::Mutate: removing field", :field=\>"host", :level=\>:debug, :file=\>"/logstash-2.2.2/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.2-java/lib/logstash/filters/base.rb", :line=\>"175", :method=\>"filter\_matched"}

{:timestamp=\>"2016-03-02T09:21:47.845000-0600", :message=\>"filters/LogStash::Filters::Mutate: removing field", :field=\>"headers", :level=\>:debug, :file=\>"/logstash-2.2.2/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.2-java/lib/logstash/filters/base.rb", :line=\>"175", :method=\>"filter\_matched"}

{:timestamp=\>"2016-03-02T09:21:47.846000-0600", :message=\>"output received", :event=\>{"LogMessage"=\>{"Header"=\>{"Source"=\>"BPM", "CreatedDateTime"=\>"2016-03-01T19:03:31.032Z", "MessageType"=\>"Event", "MessageName"=\>"CustomerCaseGraphDataService", "MessageVersio

{:timestamp=\>"2016-03-02T09:21:48.140000-0600", :message=\>"Flushing buffer at interval", :instance=\>"#\<LogStash::Outputs::ElasticSearch::Buffer:0x7f1e40ab @operations\_mutex=#Mutex:0x71d9a138, @max\_size=500, @operations\_lock=#\<Java::JavaUtilConcurrentLocks::Re

{:timestamp=\>"2016-03-02T09:21:48.202000-0600", :message=\>"Flushing buffer at interval", :instance=\>"#\<LogStash::Outputs::ElasticSearch::Buffer:0x31332f @operations\_mutex=#Mutex:0xef6dd59, @max\_size=500, @operations\_lock=#\<Java::JavaUtilConcurrentLocks::Reent

{:timestamp=\>"2016-03-02T09:21:48.278000-0600", :message=\>"Flushing buffer at interval", :instance=\>"#\<LogStash::Outputs::ElasticSearch::Buffer:0x4fde0221 @operations\_mutex=#Mutex:0x4119e5aa, @max\_size=500, @operations\_lock=#\<Java::JavaUtilConcurrentLocks::Re

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 2, 2016, 9:54pm UTC](https://discuss.elastic.co/t/how-to-increase-max-message-size/43165/4 "2016-03-02T21:54:14Z")

</div>

Is that running with `--debug`?

---

<div class="post-metadata">

**Author:** ![Junyan](https://avatars.discourse-cdn.com/v4/letter/j/a88e57/32.png) [@Junyan](https://discuss.elastic.co/u/Junyan)\
**Post date:** [March 2, 2016, 11:33pm UTC](https://discuss.elastic.co/t/how-to-increase-max-message-size/43165/5 "2016-03-02T23:33:36Z")

</div>

Yes, it is. These entries only show with --debug: :level=\>:debug

---

<div class="post-metadata">

**Author:** ![Junyan](https://avatars.discourse-cdn.com/v4/letter/j/a88e57/32.png) [@Junyan](https://discuss.elastic.co/u/Junyan)\
**Post date:** [March 8, 2016, 9:38pm UTC](https://discuss.elastic.co/t/how-to-increase-max-message-size/43165/6 "2016-03-08T21:38:02Z")

</div>

I figured this out. This is caused by a jruby bug that does not return tmpdir. Somehow I never got the exception in my dos window.

This error was reported and resolved at this url:

> <https://github.com/elastic/logstash/issues/4600>

Replacing vendor/jruby with below release solved the problem: [https://s3.amazonaws.com/jruby.org/downloads/1.7.24/jruby-bin-1.7.24.zip](https://s3.amazonaws.com/jruby.org/downloads/1.7.24/jruby-bin-1.7.24.zip)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:07am UTC](https://discuss.elastic.co/t/how-to-increase-max-message-size/43165/7 "2017-07-06T05:07:53Z")

</div>


