# How to remove restriction from the value of a field in a document such that the field doesn't get marked as \_ignored due to it's long length

**URL:** <https://discuss.elastic.co/t/how-to-remove-restriction-from-the-value-of-a-field-in-a-document-such-that-the-field-doesnt-get-marked-as-ignored-due-to-its-long-length/326727>\
**Category:** Kibana\
**Tags:** fleet\
**Created:** [March 1, 2023, 6:03am UTC](https://discuss.elastic.co/t/how-to-remove-restriction-from-the-value-of-a-field-in-a-document-such-that-the-field-doesnt-get-marked-as-ignored-due-to-its-long-length/326727 "2023-03-01T06:03:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Deepanshu\_Yadav1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_yadav1/32/117630_2.png) [@Deepanshu\_Yadav1](https://discuss.elastic.co/u/Deepanshu_Yadav1)\
**Post date:** [March 1, 2023, 6:03am UTC](https://discuss.elastic.co/t/how-to-remove-restriction-from-the-value-of-a-field-in-a-document-such-that-the-field-doesnt-get-marked-as-ignored-due-to-its-long-length/326727/1 "2023-03-01T06:03:05Z")

</div>

**PROLOGUE:**

We are using Elastic Fleet and Elastic Agents.

Using filebeat and ingest pipeline we are fetching logs from a custom log file kept on an elastic agent.

These logs are then indexed in Elastic Search and can be viewed on Kibana.

There is a field in each document named LOGS.

**PROBLEM :**

When the data is indexed, in some documents LOGS field is marked as "\_ignored" which can be seen in the Discover view.

When trying to display LOGS in the Dashboard using Top Hit aggregation, the documents which had their LOGS field marked \_ignored are not being shown.

After some digging I found out that there is a limit to how long the value of a field can be before it becomes ignored.

I want to know if there is a way to allow very long strings to get indexed without getting marked as \_ignored, and also is this restriction applied by elasticsearch or kibana ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 1, 2023, 7:08am UTC](https://discuss.elastic.co/t/how-to-remove-restriction-from-the-value-of-a-field-in-a-document-such-that-the-field-doesnt-get-marked-as-ignored-due-to-its-long-length/326727/2 "2023-03-01T07:08:24Z")

</div>

Generally you would manage this in a template that creates the index mapping.

What is the output of `GET INDEXNAME/_mapping` and which field is the one with issues?

---

<div class="post-metadata">

**Author:** ![Deepanshu\_Yadav1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_yadav1/32/117630_2.png) [@Deepanshu\_Yadav1](https://discuss.elastic.co/u/Deepanshu_Yadav1)\
**Post date:** [March 1, 2023, 10:16am UTC](https://discuss.elastic.co/t/how-to-remove-restriction-from-the-value-of-a-field-in-a-document-such-that-the-field-doesnt-get-marked-as-ignored-due-to-its-long-length/326727/3 "2023-03-01T10:16:32Z")

</div>

```auto
{
  ".ds-logs-server-wbw-2023.02.16-000001": {
    "mappings": {
      "_data_stream_timestamp": {
        "enabled": true
      },
      "dynamic_templates": [
        {
          "match_ip": {
            "match": "ip",
            "match_mapping_type": "string",
            "mapping": {
              "type": "ip"
            }
          }
        },
        {
          "match_message": {
            "match": "message",
            "match_mapping_type": "string",
            "mapping": {
              "type": "match_only_text"
            }
          }
        },
        {
          "strings_as_keyword": {
            "match_mapping_type": "string",
            "mapping": {
              "ignore_above": 1024,
              "type": "keyword"
            }
          }
        }
      ],
      "date_detection": false,
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "HASH": {
          "type": "keyword",
          "ignore_above": 1024
        },
        "LOGS": {
          "type": "keyword",
          "ignore_above": 1024
        },
        "data_stream": {
          "properties": {
            "dataset": {
              "type": "constant_keyword"
            },
            "namespace": {
              "type": "constant_keyword"
            },
            "type": {
              "type": "constant_keyword",
              "value": "logs"
            }
          }
        },
        "ecs": {
          "properties": {
            "version": {
              "type": "keyword",
              "ignore_above": 1024
            }
          }
        },
        "host": {
          "type": "object"
        },
        "message": {
          "type": "match_only_text"
        }
      }
    }
  }
}

```

Above is the output for GET INDEXNAME/\_mapping.  
Here you can see that LOGS property has a property **"ignore\_above" : 1024**

I want to increase this limit before creating the index and data stream.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2023, 10:17am UTC](https://discuss.elastic.co/t/how-to-remove-restriction-from-the-value-of-a-field-in-a-document-such-that-the-field-doesnt-get-marked-as-ignored-due-to-its-long-length/326727/4 "2023-03-29T10:17:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
