# Text getting trimmed in Kibana

**URL:** <https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607>\
**Category:** Kibana\
**Created:** [June 10, 2021, 5:25pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607 "2021-06-10T17:25:50Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![kriss332](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kriss332/32/90137_2.png) [@kriss332](https://discuss.elastic.co/u/kriss332)\
**Post date:** [June 10, 2021, 5:25pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/1 "2021-06-10T17:25:50Z")

</div>

Hi all, I've uploaded a SCV file of HTTP traffic to ELK. The file has quite large values in URL field. These values may go upto 20 lines. Kibana is not showing the complete values, which is hampering my logs analysis.  
How can I enable Kibana show the full values ?

---

<div class="post-metadata">

**Author:** ![devon.thomson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devon.thomson/32/85468_2.png) [@devon.thomson](https://discuss.elastic.co/u/devon.thomson)\
**Post date:** [June 10, 2021, 8:25pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/2 "2021-06-10T20:25:12Z")

</div>

It's a little tough to know what's going on here, I may need a bit more information from you:

If you query elasticsearch, are the whole values of the fields being shown?  
Is this in discover where the fields are being truncated?  
What is this field mapped as in your index pattern?  
Are you using an [ignore\_above](https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-above.html) setting in your mapping?

---

<div class="post-metadata">

**Author:** ![kriss332](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kriss332/32/90137_2.png) [@kriss332](https://discuss.elastic.co/u/kriss332)\
**Post date:** [June 11, 2021, 5:01am UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/3 "2021-06-11T05:01:56Z")

</div>

Thanks for reply @evon.thomson . I could see in logstash command's stdout that the entire fields were being sent through logstash and in kibana I've to expand some column58 (still 90% content is not visible, probably to save the display area ),

 ![kibana](https://us1.discourse-cdn.com/elastic/original/3X/0/6/06f50e4f29ad18a5c4d40814c6b8301e63ca7f59.png)  
I can see this column is also having **src\_content : MSQMx\u00**  **--trimmed--** kind of json mapping (but strangely no quotes). Then upon expanding this column I can see that large text.  
My config file is-

```auto
input {
        file {
                path => "/home/kriss/botsv1.stream-http.csv" 
                start_position => "beginning"
                sincedb_path => "/dev/null"
} }
filter {
	mutate {
		gsub => ['message', "\"", " "]
	}
        csv {
                separator => ","
		columns => ["_serial","_time","source","sourcetype","host,index","splunk_server","_raw"]
		# json { source => "_raw" } # I wanted to further break _raw column from CSV (since it has Json text inside it. But logstash throws error
	}
        #mutate { add_field => {"artifact" => "bots"} }              
}
output {
                elasticsearch {
                        hosts => "localhost"
                        index => "http"
                }
stdout {}
}

```

I am attaching 2 files,  
1- kibana.png shows the kibana expanded fields.  
2- kibana-input.png shows the partial view of file content being uploaded.

 ![kibana-input](https://us1.discourse-cdn.com/elastic/original/3X/4/8/488b44cb3ef894db020a495f28947217f44e640c.png)

The source CSV file is- [https://s3.amazonaws.com/botsdataset/botsv1/json-by-sourcetype/botsv1.stream-http.json.gz](https://s3.amazonaws.com/botsdataset/botsv1/json-by-sourcetype/botsv1.stream-http.json.gz) .  
I think there is no problem in Kibana receiving the data , but it is the issue of only displaying the full data. I read in a post that there is a setting in kibana to enable large text display, but couldn't find it.  
Thanks again for the kind help...

---

<div class="post-metadata">

**Author:** ![kriss332](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kriss332/32/90137_2.png) [@kriss332](https://discuss.elastic.co/u/kriss332)\
**Post date:** [June 11, 2021, 5:20am UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/4 "2021-06-11T05:20:24Z")

</div>

Also , even after selecting column 58 in the table, the data isn't fully displayed. This data is approximately 50 lines. But I can hardly see the content of 5 lines.

 ![kibana-table](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb40056f179b671a96b7ebe8a8ac353de649a6e0.png)

---

<div class="post-metadata">

**Author:** ![devon.thomson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devon.thomson/32/85468_2.png) [@devon.thomson](https://discuss.elastic.co/u/devon.thomson)\
**Post date:** [June 14, 2021, 2:55pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/5 "2021-06-14T14:55:15Z")

</div>

I'm trying to narrow down if this is a problem in discover or a problem in Logstash / with your ES mappings. Can you run a search on your `http` index, and show me if the raw JSON contains the full or truncated version of the field content?

You can go into the dev tools in kibana, and run the command `GET /http/_search`. I believe this is the right index to search, but if it doesn't work, check [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-search.html) for more information.

---

<div class="post-metadata">

**Author:** ![kriss332](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kriss332/32/90137_2.png) [@kriss332](https://discuss.elastic.co/u/kriss332)\
**Post date:** [June 14, 2021, 4:06pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/6 "2021-06-14T16:06:09Z")

</div>

Hi devon. The dev tool shows the entire data in full length. I tried to upload in pastebin but none carried full paste, the stream part gets trimmed (maybe because of certain characters of http stream). But that is really huge data.

---

<div class="post-metadata">

**Author:** ![devon.thomson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devon.thomson/32/85468_2.png) [@devon.thomson](https://discuss.elastic.co/u/devon.thomson)\
**Post date:** [June 14, 2021, 4:18pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/7 "2021-06-14T16:18:24Z")

</div>

Great, thank you for helping to narrow it down. @majagrubic, do you know anything about Discover cutting off long field contents?

@kriss332, which version of Kibana are you using?

---

<div class="post-metadata">

**Author:** ![kriss332](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kriss332/32/90137_2.png) [@kriss332](https://discuss.elastic.co/u/kriss332)\
**Post date:** [June 14, 2021, 4:40pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/8 "2021-06-14T16:40:27Z")

</div>

Thank you for following up devon. I am using kibana 7.13.1 , if I am looking at the right place in kibana dashboard.

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [June 15, 2021, 11:43am UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/9 "2021-06-15T11:43:07Z")

</div>

Just to confirm I understand the issue correctly - the data is displayed correctly when you expand the row, but not in the row in the table itself?

---

<div class="post-metadata">

**Author:** ![kriss332](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kriss332/32/90137_2.png) [@kriss332](https://discuss.elastic.co/u/kriss332)\
**Post date:** [June 16, 2021, 4:57am UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/10 "2021-06-16T04:57:10Z")

</div>

Yes majagrubic. For the huge data I've to reach out to correct column and again expand it to see full data. But in dafault discover view of kibana (even after changing it to tabular view) full data doesn't get displayed.  
Also I am facing another issue - Default discover view in kibana dowsn't show all of the fields, although these fields are there in the field selection window (in the left pane). KIbana shows only first few fields and their data (as per alphabetical order), but I can find all this data when I expand the row.

 ![kibana1](https://us1.discourse-cdn.com/elastic/original/3X/1/3/1333e9e4f6b6a399905a41a0884991e5fdd112c2.png)  
If you see in the above screenshot, last shown field is Addon but it's value got trimmed, and there are many more fields there to be shown, as below-  
 ![kibana2](https://us1.discourse-cdn.com/elastic/original/3X/a/e/ae32ba0c6c922ca9f6e7da26437912040c389cd1.png)

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [June 16, 2021, 11:30am UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/11 "2021-06-16T11:30:49Z")

</div>

What you are describing is expected behavior. We cannot show the entire data for each document as that would cause performance concerns and it wouldn't be very useful in the end. That's why expanded view is there. You can also make use of `view single document` option, which might be more readable.

---

<div class="post-metadata">

**Author:** ![kriss332](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kriss332/32/90137_2.png) [@kriss332](https://discuss.elastic.co/u/kriss332)\
**Post date:** [June 16, 2021, 5:32pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/12 "2021-06-16T17:32:14Z")

</div>

Got it @majagrubic , but you see when I have a million of logs from CSVs, it is not time efficient to expand each row and then go for "view single document". Is there any setting where I could change this ?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [June 17, 2021, 10:52am UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/13 "2021-06-17T10:52:58Z")

</div>

you can disable truncation in the table in Kibana Advanced Settings using `truncate:maxHeight`

 ![Bildschirmfoto 2021-06-17 um 12.51.37](https://us1.discourse-cdn.com/elastic/original/3X/4/3/43406bf17437e2fa5c2a0b193dab1e290f17f994.png)

---

<div class="post-metadata">

**Author:** ![kriss332](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kriss332/32/90137_2.png) [@kriss332](https://discuss.elastic.co/u/kriss332)\
**Post date:** [June 18, 2021, 6:14pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/14 "2021-06-18T18:14:43Z")

</div>

Thanks @matw. I got that option and changed it. But I ran into another problem before solving it.  
I saved some filters and then deleted some index. All of this I can't recollect exactly but can somewhat corelate now. Now all I can see is error for the index pattern. And I can't see any data even if I select any time range. Although elasticsearch query on 9200 port shows that data is there and Kibana also shows the same old indexes present.  
 ![kibana-error](https://us1.discourse-cdn.com/elastic/original/3X/b/e/be377126e6483f810300926a6848ca87fec91c5f.png)  
Whatever I do (select any index, delete existing ones, upload new CSV with a new index), doesn't solve this problem. Its been hours googling and I came across a solution - [Kibana show error index pattern - #11 by LeeDr](https://discuss.elastic.co/t/kibana-show-error-index-pattern/141022/11)  
But I cannot apply it in my kibana. Can someone guide on how to do it on v 7.13.2 ?

---

<div class="post-metadata">

**Author:** ![kriss332](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kriss332/32/90137_2.png) [@kriss332](https://discuss.elastic.co/u/kriss332)\
**Post date:** [June 21, 2021, 1:43pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/15 "2021-06-21T13:43:31Z")

</div>

Else, can someone tell me how to purge all these kind of cached configurations from kibana & elasticsearch ?

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [June 22, 2021, 3:34pm UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/16 "2021-06-22T15:34:16Z")

</div>

You will need to recreate the index pattern if you deleted it.

---

<div class="post-metadata">

**Author:** ![kriss332](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kriss332/32/90137_2.png) [@kriss332](https://discuss.elastic.co/u/kriss332)\
**Post date:** [June 27, 2021, 10:29am UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/17 "2021-06-27T10:29:49Z")

</div>

I would've done that in first choice @majagrubic , but after so many days I've even forgotten that index name. And because of this problem I had to decommission one server. I've kept it in shut state untill I find a workaround.  
Can there really not be a purging method created for such issues? Tomorrow I may have to decommission another ELK VM just because someone in my team saved the search query and I deleted the index without getting a confirmation from everyone else (and as if they remember what query they had saved).  
Plz create an alernative solve for this.

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [June 28, 2021, 9:26am UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/18 "2021-06-28T09:26:28Z")

</div>

Index pattern names are based on Elasticsearch index names. As long as your ES index is intact, you should be able to recreate an index pattern in a matter of seconds. Please read about it in our [documentation](https://www.elastic.co/guide/en/kibana/current/index-patterns.html#settings-create-pattern) and let us know if you have any more questions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2021, 9:26am UTC](https://discuss.elastic.co/t/text-getting-trimmed-in-kibana/275607/19 "2021-07-26T09:26:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
