# \[TCP Input\] Token too long

**URL:** <https://discuss.elastic.co/t/tcp-input-token-too-long/184290>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 5, 2019, 7:18am UTC](https://discuss.elastic.co/t/tcp-input-token-too-long/184290 "2019-06-05T07:18:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Valker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/valker/32/43179_2.png) [@Valker](https://discuss.elastic.co/u/Valker)\
**Post date:** [June 5, 2019, 7:18am UTC](https://discuss.elastic.co/t/tcp-input-token-too-long/184290/1 "2019-06-05T07:18:49Z")

</div>

Hello,

I think I have found an issue with the TCP input module of the Filebeat. When I tried to send multiple long json messages as a batch, while some of them are really long (like 7.5K characters), I got an error in my client:

> Unable to write data to the transport connection: An existing connection was forcibly closed by the remote host.

In the Filebeat log file there are logs:

> DEBUG [tcp] tcp/server.go:127 Client error {"address": "localhost:9123", "error": "bufio.Scanner: token too long"}  
> DEBUG [tcp] tcp/server.go:137 Client disconnected {"address": "localhost:9123", "remote\_address": "127.0.0.1:53096", "total": 2}

I think the problem is with the splitter and the MaxScanTokenSize property (which is equal to 64 \* 1024 as default).  
([Golang : Read large file with bufio.Scanner cause token too long error](https://www.socketloop.com/tutorials/golang-read-large-file-with-bufio-scanner-cause-token-too-long-error))

I am also using the file input and everything is working fine.  
I think there should be additional configuration in the TCP Input that will allow users to adjust this limit.

Kind regards,  
Michal

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [June 5, 2019, 7:50am UTC](https://discuss.elastic.co/t/tcp-input-token-too-long/184290/2 "2019-06-05T07:50:40Z")

</div>

I think you are facing this issue: [https://github.com/elastic/beats/issues/11966](https://github.com/elastic/beats/issues/11966) Correct me if I am wrong. There is a fix in progress for this: [https://github.com/elastic/beats/pull/12385](https://github.com/elastic/beats/pull/12385)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2019, 7:50am UTC](https://discuss.elastic.co/t/tcp-input-token-too-long/184290/3 "2019-07-03T07:50:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
