# Increase ignore above threshold - Kibana UI

**URL:** <https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880>\
**Category:** Kibana\
**Created:** [November 27, 2022, 1:27pm UTC](https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880 "2022-11-27T13:27:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Murali\_Y](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/murali_y/32/98137_2.png) [@Murali\_Y](https://discuss.elastic.co/u/Murali_Y)\
**Post date:** [November 27, 2022, 1:27pm UTC](https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880/1 "2022-11-27T13:27:14Z")

</div>

Hello all,  
We are using Kibana for logging/viewing/reporting our UiPath BOT logs.

But we are unable to view one field on Kibana due to the 256 characters threshold that is set on that field mapping. From [How to set the "ignore\_above" on elasticsearch / using logstash and kibana](https://discuss.elastic.co/t/how-to-set-the-ignore-above-on-elasticsearch-using-logstash-and-kibana/204683) I understand that we can update this mapping using API at index level. Can someone help with below queries:

1. Is there a way to change this 256 threshold from UI?
2. We are using monthly auto indexing (one index per month). How do we overcome the challenge of not having to update the index every month?
3. Example: If index get auto generated at 12:00 AM and we update this index at 4:00 AM. Will the logs written in these 4hrs gap gets updated with new threshold mapping and shown on Kibana? or 'Reload indices' from index management page will help us get this done?
4. Any process/steps to achieve updating mappings at whole Kibana instance level (rather than on each index)?

Version we are using: 7.16

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 27, 2022, 2:48pm UTC](https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880/2 "2022-11-27T14:48:46Z")

</div>

Hello @Murali_Y , You can use index templates and possible component templates for what you need:

> **[Index templates | Elasticsearch Guide \[7.16\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/index-templates.html)**

> **[Create or update index template API | Elasticsearch Guide \[7.16\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/indices-put-template.html)**

Just set the ignore\_above for the filed you need to something higher and all created indices that match the condition will apply everything in the template.

(There might be another template already (for example filebeat template), then you will have to update that template every update.)

Willem

---

<div class="post-metadata">

**Author:** ![Murali\_Y](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/murali_y/32/98137_2.png) [@Murali\_Y](https://discuss.elastic.co/u/Murali_Y)\
**Post date:** [November 29, 2022, 3:38pm UTC](https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880/3 "2022-11-29T15:38:18Z")

</div>

Thanks a lot for responding. Is this 256 limit only on viewing a field on Kibana UI or even the log entries will get ignored when length of field in a entry is \> 256?

---

<div class="post-metadata">

**Author:** ![Murali\_Y](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/murali_y/32/98137_2.png) [@Murali\_Y](https://discuss.elastic.co/u/Murali_Y)\
**Post date:** [November 29, 2022, 5:30pm UTC](https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880/4 "2022-11-29T17:30:30Z")

</div>

@willemdh Thanks a lot for responding. Is this 256 limit only on viewing a field on Kibana UI or even the log entries will get ignored when length of field in a entry is \> 256?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2022, 4:30pm UTC](https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880/5 "2022-12-27T16:30:56Z")

</div>



---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [December 28, 2022, 3:30pm UTC](https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880/6 "2022-12-28T15:30:15Z")

</div>

@Murali_Y from the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html#keyword-params)

> [`ignore_above`](https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-above.html)
> 
> Do not index any string longer than this value. Defaults to `2147483647` so that all values would be accepted. Please however note that default dynamic mapping rules create a sub `keyword` field that overrides this default by setting `ignore_above: 256`.

This is a setting on Elasticsearch, and not from Kibana. If this is on a `keyword` subfield, the parent field may still index the data as a `text` type, so OK for search but not for aggregation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 25, 2023, 3:30pm UTC](https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880/7 "2023-01-25T15:30:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
