# HTTP 1024 byte limit on payload

**URL:** <https://discuss.elastic.co/t/http-1024-byte-limit-on-payload/151340>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [October 7, 2018, 9:10am UTC](https://discuss.elastic.co/t/http-1024-byte-limit-on-payload/151340 "2018-10-07T09:10:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tropas](https://avatars.discourse-cdn.com/v4/letter/t/d9b06d/32.png) [@tropas](https://discuss.elastic.co/u/tropas)\
**Post date:** [October 7, 2018, 9:10am UTC](https://discuss.elastic.co/t/http-1024-byte-limit-on-payload/151340/1 "2018-10-07T09:10:42Z")

</div>

I think I've found a defect where if an http packet is \> 1024 (as defined by the content-length header) packetbeat doesn't populate the http.request.body attribute. I'm testing this with curl so it could be a way curl is constructing the payload (but I doubt it).

I've tested this with both the beats input codec and logstash as well direct in to elastic search. With both approaches where the Content-Length: \< 1024 it's fine, \> 1024 the attribute simply isn't populated.

Tested on latest stack.

Update: Turns out this is an error with CURL. Working with a different injection tool.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 9, 2018, 8:07am UTC](https://discuss.elastic.co/t/http-1024-byte-limit-on-payload/151340/2 "2018-10-09T08:07:06Z")

</div>

There is a payload size limit, but it's at 10MB.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2018, 8:07am UTC](https://discuss.elastic.co/t/http-1024-byte-limit-on-payload/151340/3 "2018-11-06T08:07:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
