# Limit of total fields ... has been exceeded

**URL:** <https://discuss.elastic.co/t/limit-of-total-fields-has-been-exceeded/216812>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 28, 2020, 10:36am UTC](https://discuss.elastic.co/t/limit-of-total-fields-has-been-exceeded/216812 "2020-01-28T10:36:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![upietz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/upietz/32/62804_2.png) [@upietz](https://discuss.elastic.co/u/upietz)\
**Post date:** [January 28, 2020, 10:36am UTC](https://discuss.elastic.co/t/limit-of-total-fields-has-been-exceeded/216812/1 "2020-01-28T10:36:05Z")

</div>

Hi there,

using winlogbeat-7.5.0-windows-x86\_64 on different Windows OS (2012R2,2016,10,...) we're regularly hitting the es (7.4.1) field limitation for our daily indices ("logstash-winlogbeat-%{+YYYY.MM}"). Logstash does no filtering, just "input { beats { port =\> 57514 } }". My questions:

- Is this expected when using winlogbeat?
- Can I configure the field limit in logstash?

If you need any further information, let me know.

Thank you!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 6, 2020, 3:16am UTC](https://discuss.elastic.co/t/limit-of-total-fields-has-been-exceeded/216812/2 "2020-02-06T03:16:26Z")

</div>

Sounds like you aren't using the index template provided by Winlogbeat. It should set a higher total field limit if used. I think it puts `index.mapping.total_fields.limit: 10000` into the index template settings.

With index naming of `logstash-winlogbeat-*` you'll need to either configure Winlogbeat with the appropriate index pattern settings before running `setup` against Elasticsearch. Or export the template to file from Winlogbeat and then hand modify it to apply to the `logstash-winlogbeat-*` index pattern. See the documentation about installing the index template for more details. [https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html#load-template-manually](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html#load-template-manually)

---

<div class="post-metadata">

**Author:** ![upietz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/upietz/32/62804_2.png) [@upietz](https://discuss.elastic.co/u/upietz)\
**Post date:** [February 17, 2020, 7:49am UTC](https://discuss.elastic.co/t/limit-of-total-fields-has-been-exceeded/216812/3 "2020-02-17T07:49:46Z")

</div>

Hi Andrew,

thanks, that was the case. We were shipping to logstash and not managing any templates.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2020, 7:49am UTC](https://discuss.elastic.co/t/limit-of-total-fields-has-been-exceeded/216812/4 "2020-03-16T07:49:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
