# Maximum allowed string Issue

**URL:** <https://discuss.elastic.co/t/maximum-allowed-string-issue/328076>\
**Category:** Elasticsearch\
**Created:** [March 20, 2023, 12:53pm UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076 "2023-03-20T12:53:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [March 20, 2023, 12:53pm UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076/1 "2023-03-20T12:53:30Z")

</div>

I get this error:  
`The content length (732630494) is bigger than the maximum allowed string (536870888)`

I added to kibana.yml:  
`server.maxPayloadBytes: 888888888`  
`savedObjects.maxImportPayloadBytes: 50485760`

I added to elasticsearch.yml: (i also got an error about Async)  
`search.max_async_search_response_size: 100mb`

Still receiving the same error:  
`The content length (732630494) is bigger than the maximum allowed string (536870888)`

What am i doing wrong???

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 20, 2023, 12:56pm UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076/2 "2023-03-20T12:56:06Z")

</div>

Why are you looking to send such immense payloads to Elasticsearch? What kind of data is it?

---

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [March 21, 2023, 10:31am UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076/3 "2023-03-21T10:31:15Z")

</div>

Well some component changed to debug mode and since then we receive this error.  
`The content length (732630494) is bigger than the maximum allowed string (536870888)` does that mean that there is a single log that is bigger then 73mb?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 21, 2023, 10:32am UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076/4 "2023-03-21T10:32:40Z")

</div>

Are you ingesting a whole log as a single document?

Elasticsearch is not designed or optimized to handle extremely large documents, so the default limits that are in place should not be modified (which I asume you have done). The standard way to deal with log data is to ingest files with each line as a single document (multiline log entries can be merged into a single document).

---

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [March 21, 2023, 11:06am UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076/5 "2023-03-21T11:06:21Z")

</div>

Thank you,  
I am not sure what I am experiancing. I checked and the longest log line did not exceed 10mb. But the file that filebeat read from was 700mb.

So not sure where this error is coming from.  
this is my filebeat settings

```auto
filebeat.inputs:
  - type: log
    enabled: true
    paths:
      - C:\ddd_logs\*\*.json
      - C:\ddd_logs\errors\*.json
    json.keys_under_root: true
    json.add_error_key: true
    json.message_key: message

setup.template.settings:
  index.number_of_shards: 1
 
output.logstash:
  
  hosts: ["xxxxxx:5044"]
  index: "testxxxx"

processors:
  - drop_fields:
      fields: ["ecs.version", "agent.ersion", "agent.type", "agent.id", "agent.hostname", "input.type", "tags", "log.flags", "agent.name", "agent.ephemeral_id"]

```

---

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [March 21, 2023, 4:21pm UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076/6 "2023-03-21T16:21:11Z")

</div>

Also, confused about general terms  
when I get this error `The content length (732630494) is bigger than the maximum allowed string (536870888)` in a search  
What does it mean?  
that the a log in my search is bigger then 732630494?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2023, 4:21pm UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076/7 "2023-04-18T16:21:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
