# Logstash Error 413

**URL:** <https://discuss.elastic.co/t/logstash-error-413/216055>\
**Category:** Logstash\
**Created:** [January 22, 2020, 12:22pm UTC](https://discuss.elastic.co/t/logstash-error-413/216055 "2020-01-22T12:22:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bhargav\_bharat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhargav_bharat/32/58025_2.png) [@bhargav\_bharat](https://discuss.elastic.co/u/bhargav_bharat)\
**Post date:** [January 22, 2020, 12:22pm UTC](https://discuss.elastic.co/t/logstash-error-413/216055/1 "2020-01-22T12:22:09Z")

</div>

Hello,

I am facing below mentioned error and logstash stop sending log to elasticsearch and communication also broken.

###########################################################

Jan 22 10:21:33 logstash\_agent logstash[29058]: [2020-01-22T10:21:33,304][ERROR][logstash.outputs.elasticsearch][main] Encountered a retryable error.  
Will Retryable error. Will Retry with exponential backoff {:code=\>413, :url=\>"htps://elasticsearc\_IP:9202/\_bulk"}

###########################################################  
Any help will be appreciated:

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 22, 2020, 2:51pm UTC](https://discuss.elastic.co/t/logstash-error-413/216055/2 "2020-01-22T14:51:23Z")

</div>

> [@bhargav\_bharat](#):
>
> htps://elasticsearc\_IP:9202/\_bulk

Really? htps?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [January 22, 2020, 9:44pm UTC](https://discuss.elastic.co/t/logstash-error-413/216055/3 "2020-01-22T21:44:30Z")

</div>

HTTP defines error code 413:

> ### 413 Payload Too Large
> 
> The 413 (Payload Too Large) status code indicates that the server is refusing to process a request because the request payload is larger than the server is willing or able to process. The server MAY close the connection to prevent the client from continuing the request. If the condition is temporary, the server SHOULD generate a Retry-After header field to indicate that it is temporary and after what time the client MAY try again.  
> -- [RFC7231 6.5.11](https://tools.ietf.org/html/rfc7231#section-6.5.11)

This response code may be coming from Elasticsearch (e.g, if the payload being sent is larger than `http.max_content_length` setting), or from an intermediate http proxy that also safeguards payload size.

The Elasticsearch Output Plugin for Logstash will by default batch multiple events into `_bulk` requests, but will only do so if it can keep the total batch size under 20MB (when it encounters a single event that is larger than 20MB, it is sent on its own).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2020, 9:44pm UTC](https://discuss.elastic.co/t/logstash-error-413/216055/4 "2020-02-19T21:44:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
