# Logstash: max\_bytes\_length\_exceeded exception

**URL:** <https://discuss.elastic.co/t/logstash-max-bytes-length-exceeded-exception/115874>\
**Category:** Logstash\
**Created:** [January 17, 2018, 12:01pm UTC](https://discuss.elastic.co/t/logstash-max-bytes-length-exceeded-exception/115874 "2018-01-17T12:01:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![annaK](https://avatars.discourse-cdn.com/v4/letter/a/e8c25b/32.png) [@annaK](https://discuss.elastic.co/u/annaK)\
**Post date:** [January 17, 2018, 12:01pm UTC](https://discuss.elastic.co/t/logstash-max-bytes-length-exceeded-exception/115874/1 "2018-01-17T12:01:12Z")

</div>

Hi all,

I have a short question, which might be very stupid indeed.

I have a document that got 34321 byte of lenght. So I get a response like

`response=>{"index"=>{"_index"=>"kafka-test-car-2018.01.15", "_type"=>"logs", "_id"=>"AWD6HJIWT8X2jMCM5ROz", "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"Document contains at least one immense term in field=\"message\" (whose UTF8 encoding is longer than the max length 32766), all of which were skipped. Please correct the analyzer to not produce such terms. The prefix of the first immense term is: '[123, 34, 104, 101, 97, 100, 101, 114, 115, 34, 58, 123, 34, 97, 101, 95, 116, 114, 97, 99, 107, 105, 110, 103, 34, 58, 34, 73, 68, 58]...', original message: bytes can be at most 32766 in length; got 34321", "caused_by"=>{"type"=>"max_bytes_length_exceeded_exception", "reason"=>"max_bytes_length_exceeded_exception: bytes can be at most 32766 in length; got 34321"}}}}`

The content of this very large field (named "message") does not need to be searchable, but I want to index it anyway. According to kibana it is of type String.

My template looks like this:

> {  
> "template" : "test-_",  
> "settings" : {  
> "index.refresh\_interval" : "15s",  
> "number\_of\_shards" : 10,  
> "number\_of\_replicas" : 0  
> },  
> "mappings" : {  
> "default" : {  
> "\_all" : {"enabled" : true},  
> "dynamic\_templates" : [ {  
> "string\_fields" : {  
> "match" : "_",  
> "match\_mapping\_type" : "string",  
> "mapping" : {  
> "type" : "string", "index" : "not\_analyzed", "omit\_norms" : true  
> }  
> }  
> } ],  
> "properties" : {  
> "@version": { "type": "string", "index": "not\_analyzed" },  
> "geoip" : {  
> "type" : "object",  
> "dynamic": true,  
> "properties" : {  
> "location" : { "type" : "geo\_point" }  
> }  
> },  
> "message":{  
> "type" : "string",  
> "index": "not\_analyzed" ,  
> "ignore\_above": 32700  
> }  
> }  
> }  
> }  
> }

But I still get the above error. What am I missing here?

Thanks in advance!  
Anna

Edit: I am using logstash 5.2 and elasticsearch 5.2

---

<div class="post-metadata">

**Author:** ![tension83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tension83/32/25044_2.png) [@tension83](https://discuss.elastic.co/u/tension83)\
**Post date:** [January 17, 2018, 2:04pm UTC](https://discuss.elastic.co/t/logstash-max-bytes-length-exceeded-exception/115874/2 "2018-01-17T14:04:58Z")

</div>

Hi,  
i thing you need this settings in your elasticsearch master node:

http.max\_initial\_line\_length:

hope this helps.

my settings is "http.max\_initial\_line\_length: 150kb"

---

<div class="post-metadata">

**Author:** ![annaK](https://avatars.discourse-cdn.com/v4/letter/a/e8c25b/32.png) [@annaK](https://discuss.elastic.co/u/annaK)\
**Post date:** [January 17, 2018, 2:14pm UTC](https://discuss.elastic.co/t/logstash-max-bytes-length-exceeded-exception/115874/3 "2018-01-17T14:14:49Z")

</div>

@tension83  
thanks for your reply 🙂

But I don't think this will help me, as this is just related to the http API. Right?  
My problem ocrurres while indexing with logstash.

---

<div class="post-metadata">

**Author:** ![annaK](https://avatars.discourse-cdn.com/v4/letter/a/e8c25b/32.png) [@annaK](https://discuss.elastic.co/u/annaK)\
**Post date:** [January 19, 2018, 7:42am UTC](https://discuss.elastic.co/t/logstash-max-bytes-length-exceeded-exception/115874/4 "2018-01-19T07:42:43Z")

</div>

Ok, I found the correct mapping via trial and error 😂  
If you have the same problem, use this:

```
{
    "template": "test-*",
    "settings": {
      "index": {
        "number_of_shards": "10",
        "number_of_replicas": "0",
        "refresh_interval": "15s"
      }
    },
    "mappings": {
      "_default_": {
        "dynamic_templates": [
          {
            "string_fields": {
              "mapping": {
                "ignore_above": 10922,
                "index": "not_analyzed",
                "omit_norms": true,
                "type": "string"
              },
              "match_mapping_type": "string",
              "match": "*"
            }
          }
        ],
        "_all": {
          "enabled": true
        },
        "properties": {
          "geoip": {
            "dynamic": true,
            "type": "object",
            "properties": {
              "location": {
                "type": "geo_point"
              }
            }
          },
          "@version": {
            "index": "not_analyzed",
            "type": "string"
          },
          "message": {
            "ignore_above": 10922,
            "index": "not_analyzed",
            "type": "string"
          }
        }
      }
    },
    "aliases": {}
  }
}

```

This topic may be closed 🙂 🌻

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 16, 2018, 7:47am UTC](https://discuss.elastic.co/t/logstash-max-bytes-length-exceeded-exception/115874/5 "2018-02-16T07:47:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
