# Limit of total fields \[1000\] in index has been exceeded

**URL:** <https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280>\
**Category:** Elasticsearch\
**Created:** [May 26, 2017, 4:00pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280 "2017-05-26T16:00:48Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_sar](https://avatars.discourse-cdn.com/v4/letter/_/ac8455/32.png) [@\_sar](https://discuss.elastic.co/u/_sar)\
**Post date:** [May 26, 2017, 4:00pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280/1 "2017-05-26T16:00:48Z")

</div>

I know how to set the total field value on an index (ES 5.x) (without to increase the default limit or decrease it) and to also use a template to apply that setting on newly created indices. However, I'm trying to better understand the ways to limit the number of fields in order not to hit the default setting. I've read some documentation, but still feel that I don't have a clear picture on how to best handle the situation. Any help is appreciated.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [May 26, 2017, 4:42pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280/2 "2017-05-26T16:42:03Z")

</div>

It looks like this is handle by the index settings `index.mapping.total_fields.limit`. So you should be able to bump that value. Just understand that more fields is more overhead and that sparse fields cause trouble. So raise it with caution. Bumping into the limit is likely a sign that you are doing something that isn't going to work well with Elasticsearch in the future.

---

<div class="post-metadata">

**Author:** ![\_sar](https://avatars.discourse-cdn.com/v4/letter/_/ac8455/32.png) [@\_sar](https://discuss.elastic.co/u/_sar)\
**Post date:** [May 26, 2017, 4:55pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280/3 "2017-05-26T16:55:18Z")

</div>

Nik,  
Thanks for the reply and I guess I wasn't clear in my question, so I edited it a bit to hopefully clarify it. I do know how to increase that value, however I prefer not to, and was just wondering about ways to handle things in order not to have that issue.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [May 26, 2017, 5:10pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280/4 "2017-05-26T17:10:09Z")

</div>

Don't make so many fields. Personally I don't like dynamic mapping. I set `"dynamic": false` which will store new fields but not index them. Then I can carefully decide which fields to add. Other folks with other use cases like `"dynamic": "strict"` which will reject changes that add new fields.

The usual strategies for making fewer fields is to combine similar ones or to use key/value objects and nested fields. key/value objects with nested fields are much slower to query than regular fields, but they don't have the sparsity storage problems. I prefer to try and lay out the data not to have so many fields. But I don't know your use case so I can't really give you any hints on how to do that.

---

<div class="post-metadata">

**Author:** ![\_sar](https://avatars.discourse-cdn.com/v4/letter/_/ac8455/32.png) [@\_sar](https://discuss.elastic.co/u/_sar)\
**Post date:** [May 30, 2017, 6:08pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280/5 "2017-05-30T18:08:44Z")

</div>

Thanks for the info Nik. I tried doing this on an existing index (have daily logs go to a daily index) that was still receiving data but the error about reaching the limit in the elasticsearch log continue which I'm guessing is because the limit has already been reached and so stopping the dynamic indexing now won't change much. I'll try setting it up as a template so that the index created tomorrow should have it. Would that stop the errors in the elasticsearch logs or do I need to do anything else. I was also wondering whether I can clear the indexed fields on the existing index to test things out

---

<div class="post-metadata">

**Author:** ![\_sar](https://avatars.discourse-cdn.com/v4/letter/_/ac8455/32.png) [@\_sar](https://discuss.elastic.co/u/_sar)\
**Post date:** [May 31, 2017, 9:06pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280/6 "2017-05-31T21:06:45Z")

</div>

The error I still receive when I try to update the index setting is the following:

> failed to put mappings on indices [[[logstash-2017.05.31/MIUnLlV7Qsq\_oe0GElLEfQ]]], type [fluentd]  
> java.lang.IllegalArgumentException: Limit of total fields [1000] in index [logstash-2017.05.31] has been exceeded

---

<div class="post-metadata">

**Author:** ![\_sar](https://avatars.discourse-cdn.com/v4/letter/_/ac8455/32.png) [@\_sar](https://discuss.elastic.co/u/_sar)\
**Post date:** [June 1, 2017, 2:20pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280/7 "2017-06-01T14:20:39Z")

</div>

After setting index.mapper.dynamic to false and applying it a new index, I now get:

> org.elasticsearch.index.query.QueryShardException: No mapping found for [@timestamp] in order to sort on

I tried adding @timestamp to the index, but that appears to have been removed in 5.0 version and looking around online, it looks like the recommendations is to configure an ingest pipeline. Is that the right route or would it better to simply re-enable dynamic mapping and create separate indices for each data source?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2017, 2:20pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded/87280/8 "2017-06-29T14:20:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
