# How to set the "ignore\_above" on elasticsearch / using logstash and kibana

**URL:** <https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683>\
**Category:** Kibana\
**Created:** [October 22, 2019, 3:30pm UTC](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683 "2019-10-22T15:30:27Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Christian\_Lorenz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_lorenz/32/56333_2.png) [@Christian\_Lorenz](https://discuss.elastic.co/u/Christian_Lorenz)\
**Post date:** [October 22, 2019, 3:30pm UTC](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683/1 "2019-10-22T15:30:27Z")

</div>

Hi,  
can anybody tell me where I can find the config, displayed in kibana to set ignore\_above to a higher value? I'm using Ubuntu.

The current 256 chars don't fit as we often get longer messages (even after parsing). Currently I've got to use the truncate filter which often cuts off relevant informations.

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [October 22, 2019, 4:30pm UTC](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683/2 "2019-10-22T16:30:10Z")

</div>

Hi @Christian_Lorenz,

Try to do a mapping on your index, see: [https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-above.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-above.html)

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![Christian\_Lorenz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_lorenz/32/56333_2.png) [@Christian\_Lorenz](https://discuss.elastic.co/u/Christian_Lorenz)\
**Post date:** [October 22, 2019, 6:59pm UTC](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683/3 "2019-10-22T18:59:14Z")

</div>

Well, yes @LizaD this was my plan. But where? We‘re using Elasticsearch 2 times: One time as a search engine, the second time for log storage. On the searching one I know where to put it. But on the 2nd installation which is basically install Elasticsearch, Logstash and Kibana and let it go I‘ve got troubles where to change it as just using Elasticsearch at the Logstash output pipelines config. So I need the config file - where it’s usually located to change this param.

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [October 22, 2019, 9:44pm UTC](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683/4 "2019-10-22T21:44:21Z")

</div>

Hi @Christian_Lorenz,

You can use curl request or Kibana Devtools console to send the API requests on the index, I am not sure ignore\_above goes into the config file itself. I will see if I can get someone to give more details.

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [October 22, 2019, 10:18pm UTC](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683/5 "2019-10-22T22:18:05Z")

</div>

I found @talevy who can give more detail on some different ways to do this.

---

<div class="post-metadata">

**Author:** ![talevy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/talevy/32/44896_2.png) [@talevy](https://discuss.elastic.co/u/talevy)\
**Post date:** [October 22, 2019, 11:15pm UTC](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683/6 "2019-10-22T23:15:11Z")

</div>

Hi @Christian_Lorenz,

Just as @LizaD recommended, I would suggest updating the `ignore_above`[[1](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/ignore-above.html)] configuration for strings in your index templates associated with your Logstash indices. This can either be done by editing the existing default logstash mapping, or by applying a new template that takes precedence [[2](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/indices-templates.html#multiple-templates)] over the existing ones.

Without knowing exactly how your Logstash mappings are determined, I will try and share a snippet of a new template that would define the behavior I believe you are hoping to modify.

```auto
PUT _template/ignore_above
{
  "index_patterns": [
    "logstash*"
  ],
  "mappings": {
    "dynamic_templates": [
      {
        "strings_as_keyword": {
          "match_mapping_type": "string",
          "mapping": {
            "type": "text",
            "fields": {
              "keyword": {
                "ignore_above": 512,
                "type": "keyword"
              }
            }
          }
        }
      }
    ]
  }
}

```

You can find the default template for Logstash and ES 7.x here [[3](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es7x.json)] You will notice that there is no explicit mention of the `ignore_above: 256` there. That is because this is a global Elasticsearch default on all dynamic fields that are recognized as strings. [Here](https://www.elastic.co/blog/strings-are-dead-long-live-strings) is a blog post that explains this. For more information about Logstash template management you can check out the [docs](https://www.elastic.co/guide/en/logstash/7.3/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-manage_template)

Does that help?

---

<div class="post-metadata">

**Author:** ![Christian\_Lorenz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_lorenz/32/56333_2.png) [@Christian\_Lorenz](https://discuss.elastic.co/u/Christian_Lorenz)\
**Post date:** [October 23, 2019, 10:25am UTC](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683/7 "2019-10-23T10:25:48Z")

</div>

Hi, thanks! Yes it worked (but strangely only after the 4th attempt) - at least on my local machine 🙂

---

<div class="post-metadata">

**Author:** ![talevy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/talevy/32/44896_2.png) [@talevy](https://discuss.elastic.co/u/talevy)\
**Post date:** [October 23, 2019, 6:27pm UTC](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683/8 "2019-10-23T18:27:04Z")

</div>

great!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2019, 6:27pm UTC](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683/9 "2019-11-20T18:27:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
