# Illegal Argument Eeption

**URL:** <https://discuss.elastic.co/t/illegal-argument-eeption/245334>\
**Category:** Elasticsearch\
**Created:** [August 18, 2020, 2:54am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334 "2020-08-18T02:54:52Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 18, 2020, 2:54am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/1 "2020-08-18T02:54:52Z")

</div>

Opening my Kibana Dashboard on my standalone ELK implementation I get the referenced error, detailed ouput below:  
`{ "took": 906, "timed_out": false, "num_reduce_phases": 8, "_shards": { "total": 74, "successful": 73, "skipped": 44, "failed": 1, "failures": [{ "shard": 0, "index": "logstash-2020.08.17-000074", "node": "O7WSf1caR3Ghkd3Zdduotg", "reason": { "type": "illegal_argument_exception", "reason": "The length of [logmessage] field of [kSsQ_3MBD8KWFJ0iW3X0] doc of [logstash-2020.08.17-000074] index has exceeded [1000000] - maximum allowed to be analyzed for highlighting. This maximum can be set by changing the [index.highlight.max_analyzed_offset] index level setting. For large texts, indexing with offsets or term vectors is recommended!" } } ] }, "hits": { "total": 808479, "max_score": null, "hits": [] } }`  
I've seen the same error for the past two weeks, it appears the error is always with the latest shard (by date).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 18, 2020, 3:00am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/2 "2020-08-18T03:00:39Z")

</div>

The log is telling you that the `logmessage` field is larger than 1000000 characters. This is explained more in [the docs](https://www.elastic.co/guide/en/elasticsearch/reference/7.8/highlighting.html#offsets-strategy).

Looks like you have some pretty large log messages being ingested? Can you see how big that field is?

---

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 18, 2020, 4:01am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/3 "2020-08-18T04:01:19Z")

</div>

How would I go about determining what message is causing it? I can't display the log messages due to the error.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 18, 2020, 4:04am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/4 "2020-08-18T04:04:37Z")

</div>

Try something like `GET logstash-2020.08.17-000074/doc/kSsQ_3MBD8KWFJ0iW3X0`

---

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 18, 2020, 4:13am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/5 "2020-08-18T04:13:16Z")

</div>

#! Deprecation: [types removal] Specifying types in document get requests is deprecated, use the /{index}/\_doc/{id} endpoint instead.  
{  
"\_index" : "logstash-2020.08.17-000074",  
"\_type" : "doc",  
"\_id" : "kSsQ\_3MBD8KWFJ0iW3X0",  
"found" : false  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 18, 2020, 4:47am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/6 "2020-08-18T04:47:38Z")

</div>

Ok, did you try that?

---

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 18, 2020, 12:31pm UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/7 "2020-08-18T12:31:54Z")

</div>

Yes, that was the output I received  
Not sure I did it from the right place - Dev Tools Console?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 18, 2020, 8:37pm UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/8 "2020-08-18T20:37:15Z")

</div>

> [@TomWBM](#):
>
> use the /{index}/\_doc/{id} endpoint instead.

Yes, but did you try the suggestion that the response gave you here?

---

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 19, 2020, 12:55am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/9 "2020-08-19T00:55:05Z")

</div>

I didn't b/c I didn't understand what it was suggesting, but after adding the leading '\_' I get this:

{  
"\_index" : "logstash-2020.08.17-000074",  
"\_type" : "\_doc",  
"\_id" : "kSsQ\_3MBD8KWFJ0iW3X0",  
"\_version" : 1,  
"\_seq\_no" : 3654,  
"\_primary\_term" : 1,  
"found" : true,  
"\_source" : {  
"applicationlog" : "ics-orders-to-salesforce-service",  
"eventtime" : "2020-08-17 20:55:17,512",  
"host" : {  
"hostname" : "emtmulc1p006",  
"containerized" : false,  
"id" : "76ba8ef5ccad46c387142217853051a1",  
"name" : "emtmulc1p006",  
"architecture" : "x86\_64",  
"os" : {  
"name" : "SLES",  
"kernel" : "4.4.180-94.116-default",  
"version" : "12-SP3",  
"family" : "suse",  
"platform" : "sles"  
}  
},  
"agent" : {  
"type" : "filebeat",  
"id" : "9fba55f5-1a50-4c5a-b910-7659f1369467",  
"ephemeral\_id" : "9b46f932-9b66-41a1-a5a7-383badb27ade",  
"version" : "7.6.2",  
"hostname" : "emtmulc1p006"  
},  
"input" : {  
"type" : "log"  
},  
"@timestamp" : "2020-08-18T00:55:17.512Z",  
"message" : """2020-08-17 20:55:17,512 INFO \<\<TRUNCATED, 4442 LINES of application specific data REDACTED\>\>  
"loglevel" : "INFO",  
"tags" : [  
"beats\_input\_codec\_plain\_applied"  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 19, 2020, 1:51am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/10 "2020-08-19T01:51:10Z")

</div>

> [@TomWBM](#):
>
> \<\<TRUNCATED, 4442 LINES of application specific data REDACTED\>\>

If this is you that has added the truncated/redacted info, and it is indeed 4422 lines, that's a pretty massive log file.

What sort of data is this?

> [@TomWBM](#):
>
> I didn't b/c I didn't understand what it was suggesting

That's ok, but you should let us know so we understand what you need help with 🙂

---

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 19, 2020, 1:55am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/11 "2020-08-19T01:55:39Z")

</div>

Customer Order information. we see a couple of these (this size) a day usually.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 19, 2020, 2:01am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/12 "2020-08-19T02:01:47Z")

</div>

Ok, so if you copy that field into a text editor, how many characters is it?

---

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 19, 2020, 2:02am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/13 "2020-08-19T02:02:58Z")

</div>

3,189,928

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 19, 2020, 2:06am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/14 "2020-08-19T02:06:20Z")

</div>

You could increase `index.highlight.max_analyzed_offset` to 4 million, as per the link in my first response. That'll remove the error, but it's likely to be pretty expensive, which will have larger impacts. As that doc suggests;

> Plain highlighting for large texts may require substantial amount of time and memory

I'm not 100% sure what approach to take here. Is the error on the dashboard causing any problems, or can you just accept it?

---

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 19, 2020, 2:10am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/15 "2020-08-19T02:10:39Z")

</div>

Most of the time it causes Kibana to not display messages on the dashboard. For my App team, it's a deal breaker. I've considered 'The postings list', but I'm not sure of what all I'd need to change to accomodate.

---

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 20, 2020, 9:44pm UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/16 "2020-08-20T21:44:28Z")

</div>

ok, so If I gather correctly, what I want to do is modify the -template that is processing this data. Initially, I will open the flood gates, so to speak , and allow 5M v 1M, to do this I'm going to use the DEV Tool and:  
PUT \_template/logstash  
{  
"settings": {  
"index": {  
"highlight": {  
"max\_analyzed\_offset": "5000000"  
}  
}  
}  
)  
If this ounds and looks right to you, I'm going to give it a go.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 21, 2020, 1:06am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/17 "2020-08-21T01:06:24Z")

</div>

That syntax looks ok.

---

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 29, 2020, 1:01am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/18 "2020-08-29T01:01:17Z")

</div>

it wasn't. any suggestions?

---

<div class="post-metadata">

**Author:** ![TomWBM](https://avatars.discourse-cdn.com/v4/letter/t/a8b319/32.png) [@TomWBM](https://discuss.elastic.co/u/TomWBM)\
**Post date:** [August 29, 2020, 2:00am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/19 "2020-08-29T02:00:21Z")

</div>

NVM\> I figured it out. I t wants the expanded json set, not just whayt I wanted changed:

PUT \_template/logstash  
{  
"order" : 0,  
"version" : 60001,  
"index\_patterns" : [  
"logstash-_"  
],  
"settings": {  
"index": {  
"highlight": {  
"max\_analyzed\_offset": "5000000"  
},  
"lifecycle" : {  
"name" : "logstash-policy",  
"rollover\_alias" : "logstash"  
},  
"number\_of\_shards" : "1",  
"refresh\_interval" : "5s"  
}  
},  
"mappings" : {  
"\_meta" : { },  
"\_source" : { },  
"dynamic\_templates" : [  
{  
"message\_field" : {  
"path\_match" : "message",  
"mapping" : {  
"norms" : false,  
"type" : "text"  
},  
"match\_mapping\_type" : "string"  
}  
},  
{  
"string\_fields" : {  
"mapping" : {  
"norms" : false,  
"type" : "text",  
"fields" : {  
"keyword" : {  
"ignore\_above" : 256,  
"type" : "keyword"  
}  
}  
},  
"match\_mapping\_type" : "string",  
"match" : "_"  
}  
}  
],  
"properties" : {  
"@timestamp" : {  
"type" : "date"  
},  
"geoip" : {  
"dynamic" : true,  
"type" : "object",  
"properties" : {  
"ip" : {  
"type" : "ip"  
},  
"latitude" : {  
"type" : "half\_float"  
},  
"location" : {  
"type" : "geo\_point"  
},  
"longitude" : {  
"type" : "half\_float"  
}  
}  
},  
"@version" : {  
"type" : "keyword"  
}  
}  
},  
"aliases" : { }  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2020, 2:00am UTC](https://discuss.elastic.co/t/illegal-argument-eeption/245334/20 "2020-09-26T02:00:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
