# Http.max\_content\_length update on cluster

**URL:** <https://discuss.elastic.co/t/http-max-content-length-update-on-cluster/301476>\
**Category:** Elasticsearch\
**Created:** [April 4, 2022, 9:03am UTC](https://discuss.elastic.co/t/http-max-content-length-update-on-cluster/301476 "2022-04-04T09:03:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gerasimysys](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerasimysys/32/103903_2.png) [@gerasimysys](https://discuss.elastic.co/u/gerasimysys)\
**Post date:** [April 4, 2022, 9:03am UTC](https://discuss.elastic.co/t/http-max-content-length-update-on-cluster/301476/1 "2022-04-04T09:03:30Z")

</div>

Hello.  
On the logstash, have error

```auto
[ERROR][logstash.outputs.elasticsearch][main][4662344eb1eeab4baf336e2996a14ddadf8c61b8943c6e31c68cb582d77f72de] Encountered a retryable error (will retry with exponential ba
ckoff) {:code=>413, :url=>"http://elasticsearch-server:9200/_bulk", :content_length=>121168835}

```

How can i change the value "http.max\_content\_length: 200mb" on the whole cluster?  
Thanks.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 4, 2022, 11:13am UTC](https://discuss.elastic.co/t/http-max-content-length-update-on-cluster/301476/2 "2022-04-04T11:13:09Z")

</div>

Hey,

this can only be configured statically in the configuration file or via properties on startup. Is there any chance to send smaller bulks? Out of curiosity: Why did you pick this value? Did you pick that value based on testing?

--Alex

--Alex

---

<div class="post-metadata">

**Author:** ![gerasimysys](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerasimysys/32/103903_2.png) [@gerasimysys](https://discuss.elastic.co/u/gerasimysys)\
**Post date:** [April 4, 2022, 2:32pm UTC](https://discuss.elastic.co/t/http-max-content-length-update-on-cluster/301476/3 "2022-04-04T14:32:13Z")

</div>

Hello, Alex.  
We pick this value because i find [Encountered a retryable error (will retry with exponential backoff) {:code=\>413,](https://discuss.elastic.co/t/encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413/291417)

You suggest to leave this value by default. And look in the direction of reducing the input data from logstash.  
Because in the future it will affect the performance of the cluster?

Also set this value. Because the data did not go to Elasticsearch. After restarting logstash, the data was uploaded correctly.

And this setting «http.max\_content\_length: 200mb» should be specified on all nodes of the cluster (master, data) or only on those where logstash output looks?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 5, 2022, 7:16am UTC](https://discuss.elastic.co/t/http-max-content-length-update-on-cluster/301476/4 "2022-04-05T07:16:25Z")

</div>

So, logstash will by default only go up to a maximum size of 20MB for its data... **unless** you are sending massive single documents.

Do you have a single document exceeding 100MB in size?

---

<div class="post-metadata">

**Author:** ![gerasimysys](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerasimysys/32/103903_2.png) [@gerasimysys](https://discuss.elastic.co/u/gerasimysys)\
**Post date:** [April 5, 2022, 11:19am UTC](https://discuss.elastic.co/t/http-max-content-length-update-on-cluster/301476/5 "2022-04-05T11:19:24Z")

</div>

Hello, Alex  
I think yes, because we have 8 inputs on logstash:  
4 json\_lines  
3 json  
1 beats

```auto
input {
    beats {
        port => 5044
        ssl => false
    }
}

input {
    tcp {
        port => 5045
        codec => json_lines
        type => "name-1-log"
    }
}

input {
    tcp {
        port => 5046
        codec => json_lines
        type => "name-2-log-demo"
    }
}

input {
    tcp {
        port => 5047
        codec => json_lines
        type => "name-3"
    }
}

input {
    tcp {
        port => 5048
        codec => json_lines
        type => "name-4"
    }
}

input {
    tcp {
        port => 5049
        codec => json
        type => "name-5"
       }
}
input {
    tcp {
        port => 5050
        codec => json
        type => "name-6"
    }
}

input {
    tcp {
        port => 5051
        codec => json
        type => "name-7"
    }
}

```

Since they accept all connections at the same time, in total there is an excess of 100 megabytes.  
Or am I wrong?  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2022, 11:19am UTC](https://discuss.elastic.co/t/http-max-content-length-update-on-cluster/301476/6 "2022-05-03T11:19:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
