# Logstash 7.0.1 not work line too large

**URL:** <https://discuss.elastic.co/t/logstash-7-0-1-not-work-line-too-large/180854>\
**Category:** Logstash\
**Created:** [May 13, 2019, 5:42pm UTC](https://discuss.elastic.co/t/logstash-7-0-1-not-work-line-too-large/180854 "2019-05-13T17:42:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tavellahh](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@tavellahh](https://discuss.elastic.co/u/tavellahh)\
**Post date:** [May 13, 2019, 5:42pm UTC](https://discuss.elastic.co/t/logstash-7-0-1-not-work-line-too-large/180854/1 "2019-05-13T17:42:03Z")

</div>

Hi, I am having problems when I try to read a log file, which has lines of more than 8000 characters in length each, is it possible that logstash has a limitation about this, or do I have to configure something to work correctly?

This is my match filter.

match =\> {"message" =\> "%{DATA:Fecha}\s%{DATA:Hora}\s%{DATA:Domain}\s%{LOGLEVEL:NivelLog}\s%{DATA:LoggerMessageProcessor}\s-\smessage.id:\s%{DATA:message}\s/\sRESPONSE HOST:\s%{GREEDYDATA:RESPONSE}.\*"}

And this is a tipical line of log:  
2019-04-30 10:41:22,982 [[banco\_provincia\_legacy\_domain].HTTP\_LISTENER\_GENERAL.worker.1340] INFO org.mule.api.processor.LoggerMessageProcessor - message.id: a496f080-6b4d-11e9-b6d6-005056a84e5a / RESPONSE HOST: OK|44|LA PROPUESTA LA TIENE EN ESTE MOMENTO EL TERM  
(for try this, add at the end of this lines 6000 spaces)

Thank you.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 13, 2019, 5:44pm UTC](https://discuss.elastic.co/t/logstash-7-0-1-not-work-line-too-large/180854/2 "2019-05-13T17:44:36Z")

</div>

What error are you seeing? What does your config look like?

---

<div class="post-metadata">

**Author:** ![tavellahh](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@tavellahh](https://discuss.elastic.co/u/tavellahh)\
**Post date:** [May 14, 2019, 1:04pm UTC](https://discuss.elastic.co/t/logstash-7-0-1-not-work-line-too-large/180854/3 "2019-05-14T13:04:19Z")

</div>

```
# Sample Logstash configuration for creating a simple
# Beats -> Logstash -> Elasticsearch pipeline.

input {

	file{
		path => "C:/SuiteElastic/logs/*.log"
		start_position => "beginning"
		sincedb_path => "C:/SuiteElastic/since"
		codec => plain {
                    charset => "ISO-8859-1"
           }
		   

	}
	#beats {
	# port => 5044
	#	}
}

filter {

	grok {
		#break_on_match => false
		#match => {"message" => "Marca: %{DATA:Marca} - Color: %{DATA:Color} - Modelo: %{GREEDYDATA:Modelo}"}
		match => {"message" => "%{DATA:Fecha}\s%{DATA:Hora}\s%{DATA:Domain}\s%{LOGLEVEL:NivelLog}\s%{DATA:LoggerMessageProcessor}\s-\smessage.id:\s%{DATA:message}\s/\sIP\sProcess:\s/%{URIHOST:IP Process}\s/\smessageIdProcess:\s%{DATA:messageIdProcess}\s/\sREQUEST HOST:\s%{GREEDYDATA:REQUEST}"}	
	}
	if "REQUEST" not in [tags] {
		grok {
			#match => {"message" => "Nombre: %{DATA:Nombre} - Apellido: %{DATA:Apellido} - DNI: %{GREEDYDATA:DNI}"}
			match => {"message" => "%{DATA:Fecha}\s%{DATA:Hora}\s%{DATA:Domain}\s%{LOGLEVEL:NivelLog}\s%{DATA:LoggerMessageProcessor}\s-\smessage.id:\s%{DATA:message}\s/\sRESPONSE HOST:\s%{GREEDYDATA:RESPONSE}.*"}
			remove_tag => ["_grokparsefailure"]
		}
	}

}

output {
stdout {}
  file {
    path => "C:/SuiteElastic/test.log" 
  }
  #elasticsearch {
    #hosts => ["http://127.0.0.1:9200/"]
    #index => "indice_1"
    #user => "elastic"
    #password => "changeme"
  #}
}

```

This is the config file, the error is that with large files doesn't log all lines, but if i remove the spaces at the end of each line it work fine, (i try this with the same file), is very is strange .

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 14, 2019, 1:38pm UTC](https://discuss.elastic.co/t/logstash-7-0-1-not-work-line-too-large/180854/4 "2019-05-14T13:38:22Z")

</div>

Do you have a line feed st the end of every event? How many events are missing ssinf?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2019, 1:38pm UTC](https://discuss.elastic.co/t/logstash-7-0-1-not-work-line-too-large/180854/5 "2019-06-11T13:38:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
