# Json message not available in the ELK-stack

**URL:** <https://discuss.elastic.co/t/json-message-not-available-in-the-elk-stack/140754>\
**Category:** Logstash\
**Created:** [July 19, 2018, 2:14pm UTC](https://discuss.elastic.co/t/json-message-not-available-in-the-elk-stack/140754 "2018-07-19T14:14:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![twan](https://avatars.discourse-cdn.com/v4/letter/t/a587f6/32.png) [@twan](https://discuss.elastic.co/u/twan)\
**Post date:** [July 19, 2018, 2:14pm UTC](https://discuss.elastic.co/t/json-message-not-available-in-the-elk-stack/140754/1 "2018-07-19T14:14:19Z")

</div>

Hi there,

We've ran into a problem within our ELK-stack. We have an application that logs in json format.  
When there is an error the application adds an field called "stack\_trace". In this field is the stack trace parsed (obviously).

We use the JSON filter plugin for Logstash. If the stack\_trace field is present with an very big stack trace, the event is not send to Elasticsearch, and we also cannot find it on the persistent queue.

Is there a limit to what size a single field in the JSON message can be?  
_If there is a small stack trace in the field, the message is send to ES._

Or can it be that the whole message is getting to large with a big stack trace in it?

There is no error in the logging of Filebeat, Logstash, Elasticsearch regarding this problem.  
We are running version 6.3.1 of the Elastic stack.

If you need more information, please ask 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 19, 2018, 8:44pm UTC](https://discuss.elastic.co/t/json-message-not-available-in-the-elk-stack/140754/2 "2018-07-19T20:44:42Z")

</div>

> [@twan](#):
>
> the field is not send to Elasticsearch

The field is not sent, or the event is not sent? Are you saying the event is put into elasticsearch without the over-sized stack trace?

---

<div class="post-metadata">

**Author:** ![twan](https://avatars.discourse-cdn.com/v4/letter/t/a587f6/32.png) [@twan](https://discuss.elastic.co/u/twan)\
**Post date:** [July 20, 2018, 8:54am UTC](https://discuss.elastic.co/t/json-message-not-available-in-the-elk-stack/140754/3 "2018-07-20T08:54:02Z")

</div>

Ah sorry, the complete event is not send to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![twan](https://avatars.discourse-cdn.com/v4/letter/t/a587f6/32.png) [@twan](https://discuss.elastic.co/u/twan)\
**Post date:** [July 26, 2018, 1:06pm UTC](https://discuss.elastic.co/t/json-message-not-available-in-the-elk-stack/140754/4 "2018-07-26T13:06:57Z")

</div>

Does anyone know why this is happening?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2018, 1:06pm UTC](https://discuss.elastic.co/t/json-message-not-available-in-the-elk-stack/140754/5 "2018-08-23T13:06:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
