# The content length (938946807) is bigger than the maximum allowed string (536870888) sending logstash-plain.log to elasticsearch

**URL:** <https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533>\
**Category:** Logstash\
**Created:** [November 22, 2022, 9:44am UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533 "2022-11-22T09:44:17Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [November 22, 2022, 9:44am UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533/1 "2022-11-22T09:44:17Z")

</div>

Hi I have setup filebeat to send logstash logs to logstah then elasticsearch. Getting this error when trying to access it on discover page

```auto
Search Error
The content length (938946807) is bigger than the maximum allowed string (536870888)

Error: The content length (938946807) is bigger than the maximum allowed string (536870888)
    at search_interceptor_SearchInterceptor.handleSearchError (http://43.204.205.20:5601/57136/bundles/plugin/data/kibana/data.plugin.js:1:411520)
    at http://43.204.205.20:5601/57136/bundles/plugin/data/kibana/data.plugin.js:1:414261
    at http://43.204.205.20:5601/57136/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:334:699372
    at s._error (http://43.204.205.20:5601/57136/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:6:33819)
    at t.error (http://43.204.205.20:5601/57136/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:334:97199)
    at http://43.204.205.20:5601/57136/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:329:45177
    at o (http://43.204.205.20:5601/57136/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:334:262880)
    at t.error (http://43.204.205.20:5601/57136/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:329:45044)
    at Object.error (http://43.204.205.20:5601/57136/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:334:445442)
    at e.error (http://43.204.205.20:5601/57136/bundles/kbn-ui-shared-deps-npm/kbn-ui-shared-deps-npm.dll.js:334:98005)

```

```auto
- type: log

  enabled: true
  paths:
    - /var/log/logstash/*.log
  fields:
    type: logstash_syslog
  fields_under_root: true

```

pipeline.conf

```auto
input {
  beats {
    port => 5044
  }
}

output {
  elasticsearch {
    hosts => "http://localhost:9200"
    index => "%{type}%{+YYYY.MM.dd}"
    user => "user"
    password => "pwd"
  }
}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 22, 2022, 10:15am UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533/2 "2022-11-22T10:15:36Z")

</div>

I think this is error related to Kibana.

_Error: The content length (938946807) is bigger than the maximum allowed string (536870888)  
at search\_interceptor\_SearchInterceptor.handleSearchError ([http://ip:5601/57136/bundles/plugin/data/kibana/data.plugin.js:1:411520](http://ip:5601/57136/bundles/plugin/data/kibana/data.plugin.js:1:411520))_

Set `server.maxPayloadBytes: 1938946807` in kibana.yml, restart kibana and test.

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [November 22, 2022, 11:55am UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533/3 "2022-11-22T11:55:43Z")

</div>

getting this after adding server.maxPayloadBytes

```auto
Nov 22 11:54:16 ip-10-0-9-223.ap-south-1.compute.internal kibana[7557]: [2022-11-22T11:54:16.940+00:00][WARN][plugins.licensing] License information could not be obtained from Elasticsearch due to ConnectionError: connect ECONNREFUSED 10.0.9.223:9200 error
Nov 22 11:54:19 ip-10-0-9-223.ap-south-1.compute.internal kibana[7557]: [2022-11-22T11:54:19.017+00:00][ERROR][plugins.security.authentication] License is not available, authentication is not possible.
Nov 22 11:54:19 ip-10-0-9-223.ap-south-1.compute.internal kibana[7557]: [2022-11-22T11:54:19.022+00:00][WARN][plugins.licensing] License information could not be obtained from Elasticsearch due to ConnectionError: connect ECONNREFUSED 10.0.9.223:9200 error
Nov 22 11:54:19 ip-10-0-9-223.ap-south-1.compute.internal kibana[7557]: [2022-11-22T11:54:19.196+00:00][ERROR][plugins.security.authentication] License is not available, authentication is not possible.
Nov 22 11:54:19 ip-10-0-9-223.ap-south-1.compute.internal kibana[7557]: [2022-11-22T11:54:19.203+00:00][WARN][plugins.licensing] License information could not be obtained from Elasticsearch due to ConnectionError: connect ECONNREFUSED 10.0.9.223:9200 error
Nov 22 11:54:20 ip-10-0-9-223.ap-south-1.compute.internal kibana[7557]: [2022-11-22T11:54:20.861+00:00][WARN][plugins.licensing] License information could not be obtained from Elasticsearch due to ConnectionError: connect ECONNREFUSED 10.0.9.223:9200 error
Nov 22 11:54:21 ip-10-0-9-223.ap-south-1.compute.internal kibana[7557]: [2022-11-22T11:54:21.476+00:00][ERROR][plugins.security.authentication] License is not available, authentication is not possible.
Nov 22 11:54:21 ip-10-0-9-223.ap-south-1.compute.internal kibana[7557]: [2022-11-22T11:54:21.481+00:00][WARN][plugins.licensing] License information could not be obtained from Elasticsearch due to ConnectionError: connect ECONNREFUSED 10.0.9.223:9200 error
Nov 22 11:54:21 ip-10-0-9-223.ap-south-1.compute.internal kibana[7557]: [2022-11-22T11:54:21.668+00:00][ERROR][plugins.security.authentication] License is not available, authentication is not possible.
Nov 22 11:54:21 ip-10-0-9-223.ap-south-1.compute.internal kibana[7557]: [2022-11-22T11:54:21.676+00:00][WARN][plugins.licensing] License information could not be obtained from Elasticsearch due to ConnectionError: connect ECONNREFUSED 10.0.9.223:9200 error

```

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [November 22, 2022, 11:58am UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533/4 "2022-11-22T11:58:32Z")

</div>

strange. everything worked fine till now! even if i undo the change getting this error now

```auto
[ERROR][elasticsearch-service] Unable to retrieve version information from Elasticsearch nodes. connect ECONNREFUSED 10.0.9.223:9200

```

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [November 22, 2022, 12:06pm UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533/6 "2022-11-22T12:06:22Z")

</div>

i am unable to curl to localhost:9200 ip:9200? kibana works fine for sometime and then elasticsearch fails

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [November 22, 2022, 12:08pm UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533/7 "2022-11-22T12:08:48Z")

</div>

```auto
Nov 22 11:59:47 ip-10-0-9-223.ap-south-1.compute.internal systemd[1]: Starting Elasticsearch...
Nov 22 12:00:12 ip-10-0-9-223.ap-south-1.compute.internal systemd[1]: Started Elasticsearch.
Nov 22 12:03:33 ip-10-0-9-223.ap-south-1.compute.internal systemd-entrypoint[7689]: java.lang.OutOfMemoryError: Java heap space
Nov 22 12:03:33 ip-10-0-9-223.ap-south-1.compute.internal systemd-entrypoint[7689]: Dumping heap to /var/lib/elasticsearch/java_pid7753.hprof ...
Nov 22 12:03:44 ip-10-0-9-223.ap-south-1.compute.internal systemd-entrypoint[7689]: Heap dump file created [1830582675 bytes in 10.572 secs]
Nov 22 12:03:44 ip-10-0-9-223.ap-south-1.compute.internal systemd-entrypoint[7689]: Terminating due to java.lang.OutOfMemoryError: Java heap space
Nov 22 12:03:44 ip-10-0-9-223.ap-south-1.compute.internal systemd-entrypoint[7689]: ERROR: Elasticsearch exited unexpectedly

```

was facing the same issue previously. made changes to jvm options in elasticsearch and logstash to 2g. my machine is 8gb ram 50 gb hardisk. with elk+filebeat on it. what should be the settings?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 22, 2022, 12:32pm UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533/8 "2022-11-22T12:32:34Z")

</div>

You have issue with Elasticsearch.  
By default ES use 50% of RAM, if you haven't set in jvm.options

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [November 22, 2022, 12:45pm UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533/9 "2022-11-22T12:45:23Z")

</div>

Currently elasticsearch jvm options is set to 2g. And logstash jvm options is set to 2g. Is that ok ?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 22, 2022, 1:00pm UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533/10 "2022-11-22T13:00:00Z")

</div>

2GB for ES is too low, put at least 4 or 8 GB.  
For LS, 2 GB should be OK, if you don't have much data, roughly say 5-7 000/sec for 1 GB.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2022, 1:00pm UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533/11 "2022-12-20T13:00:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
