# "The incoming YAML document exceeds the limit: 3145728 code points" in Logstash/ElastiFLOW

**URL:** <https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803>\
**Category:** Logstash\
**Created:** [May 31, 2023, 12:48pm UTC](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803 "2023-05-31T12:48:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![numpty-boy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/numpty-boy/32/137176_2.png) [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Post date:** [May 31, 2023, 12:48pm UTC](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803/1 "2023-05-31T12:48:41Z")

</div>

Since upgrading to logstash 7.17.10 on Centos 7, I've been seeing the above error when starting.

I see some other folks have had similar problems 8.7, and there are similar problems reported in RUBY forums.

I had no such problems with 7.17.9. FYI, I'm running ElastiFLOW on top of Logstash.

The full log entry is as follows:  
[2023-05-31T13:12:26,334][ERROR][logstash.javapipeline][elastiflow] Pipeline error {:pipeline\_id=\>"elastiflow", :exception=\>#\<LogStash::Filters::Dictionary::DictionaryFileError: Translate: The incoming YAML document exceeds the limit: 3145728 code points. when loading dictionary file at /etc/logstash/elastiflow/dictionaries/ip\_rep\_basic.yml\>, :backtrace=\>["org.yaml.snakeyaml.scanner.ScannerImpl.fetchMoreTokens(ScannerImpl.java:342)", "org.yaml.snakeyaml.scanner.ScannerImpl.checkToken(ScannerImpl.java:263)", "org.yaml.snakeyaml.parser.ParserImpl$ParseBlockMappingKey.produce(ParserImpl.java:662)", "org.yaml.snakeyaml.parser.ParserImpl.peekEvent(ParserImpl.java:185)", "org.yaml.snakeyaml.parser.ParserImpl.getEvent(ParserImpl.java:195)", "org.jruby.ext.psych.PsychParser.parse(PsychParser.java:199)", "uri\_3a\_classloader\_3a\_.META\_minus\_INF.jruby\_dot\_home.lib.ruby.stdlib.psych.RUBY$method$parse\_stream$0(uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/psych.rb:457)", "usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.logstash\_minus\_filter\_minus\_translate\_minus\_3\_dot\_3\_dot\_1.lib.logstash.filters.dictionary.yaml\_file.RUBY$method$read\_file\_into\_dictionary$0(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-translate-3.3.1/lib/logstash/filters/dictionary/yaml\_file.rb:19)", "usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.logstash\_minus\_filter\_minus\_translate\_minus\_3\_dot\_3\_dot\_1.lib.logstash.filters.dictionary.file.RUBY$method$merge\_dictionary$0(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-translate-3.3.1/lib/logstash/filters/dictionary/file.rb:101)", "org.jruby.internal.runtime.methods.CompiledIRMethod.call(CompiledIRMethod.java:93)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:105)", "org.jruby.RubyMethod.call(RubyMethod.java:115)", "usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.logstash\_minus\_filter\_minus\_translate\_minus\_3\_dot\_3\_dot\_1.lib.logstash.filters.dictionary.file.RUBY$method$load\_dictionary$0(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-translate-3.3.1/lib/logstash/filters/dictionary/file.rb:66)", "usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.logstash\_minus\_filter\_minus\_translate\_minus\_3\_dot\_3\_dot\_1.lib.logstash.filters.dictionary.file.RUBY$method$initialize$0(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-translate-3.3.1/lib/logstash/filters/dictionary/file.rb:53)", "usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.logstash\_minus\_filter\_minus\_translate\_minus\_3\_dot\_3\_dot\_1.lib.logstash.filters.dictionary.file.RUBY$method$create$0(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-translate-3.3.1/lib/logstash/filters/dictionary/file.rb:15)", "usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.logstash\_minus\_filter\_minus\_translate\_minus\_3\_dot\_3\_dot\_1.lib.logstash.filters.translate.RUBY$method$register$0(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-translate-3.3.1/lib/logstash/filters/translate.rb:181)", "org.jruby.internal.runtime.methods.CompiledIRMethod.call(CompiledIRMethod.java:93)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:105)", "org.jruby.internal.runtime.methods.DynamicMethod.call(DynamicMethod.java:192)", "org.jruby.RubyClass.finvoke(RubyClass.java:572)", "org.jruby.runtime.Helpers.invoke(Helpers.java:635)", "org.jruby.RubyBasicObject.callMethod(RubyBasicObject.java:354)", "org.logstash.config.ir.compiler.FilterDelegatorExt.doRegister(FilterDelegatorExt.java:88)", "org.logstash.config.ir.compiler.AbstractFilterDelegatorExt.register(AbstractFilterDelegatorExt.java:75)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$block$register\_plugins$1(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:233)", "org.jruby.runtime.CompiledIRBlockBody.yieldDirect(CompiledIRBlockBody.java:148)", "org.jruby.runtime.BlockBody.yield(BlockBody.java:106)", "org.jruby.runtime.Block.yield(Block.java:184)", "org.jruby.RubyArray.each(RubyArray.java:1821)", "org.jruby.RubyArray$INVOKER$i$0$0$each.call(RubyArray$INVOKER$i$0$0$each.gen)", "org.jruby.internal.runtime.methods.JavaMethod$JavaMethodZeroBlock.call(JavaMethod.java:555)", "org.jruby.ir.targets.InvokeSite.invoke(InvokeSite.java:197)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$register\_plugins$0(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:232)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$register\_plugins$0$ **VARARGS** (/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:230)", "org.jruby.internal.runtime.methods.CompiledIRMethod.call(CompiledIRMethod.java:80)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:70)", "org.jruby.ir.targets.InvokeSite.invoke(InvokeSite.java:207)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$maybe\_setup\_out\_plugins$0(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:599)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$maybe\_setup\_out\_plugins$0$ **VARARGS** (/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:596)", "org.jruby.internal.runtime.methods.CompiledIRMethod.call(CompiledIRMethod.java:80)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:70)", "org.jruby.ir.targets.InvokeSite.invoke(InvokeSite.java:207)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$start\_workers$0(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:245)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$start\_workers$0$ **VARARGS** (/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:241)", "org.jruby.internal.runtime.methods.CompiledIRMethod.call(CompiledIRMethod.java:80)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:70)", "org.jruby.ir.targets.InvokeSite.invoke(InvokeSite.java:207)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$run$0(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:190)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$run$0$ **VARARGS** (/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:185)", "org.jruby.internal.runtime.methods.CompiledIRMethod.call(CompiledIRMethod.java:80)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:70)", "org.jruby.ir.targets.InvokeSite.invoke(InvokeSite.java:207)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$block$start$1(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:142)", "org.jruby.runtime.CompiledIRBlockBody.callDirect(CompiledIRBlockBody.java:138)", "org.jruby.runtime.IRBlockBody.call(IRBlockBody.java:58)", "org.jruby.runtime.IRBlockBody.call(IRBlockBody.java:52)", "org.jruby.runtime.Block.call(Block.java:139)", "org.jruby.RubyProc.call(RubyProc.java:318)", "org.jruby.internal.runtime.RubyRunnable.run(RubyRunnable.java:105)", "java.base/java.lang.Thread.run(Thread.java:829)"], "pipeline.sources"=\>["/etc/logstash/elastiflow/conf.d/10\_input\_ipfix\_ipv4.logstash.conf", "/etc/logstash/elastiflow/conf.d/10\_input\_netflow\_ipv4.logstash.conf", "/etc/logstash/elastiflow/conf.d/10\_input\_sflow\_ipv4.logstash.conf", "/etc/logstash/elastiflow/conf.d/20\_filter\_10\_begin.logstash.conf", "/etc/logstash/elastiflow/conf.d/20\_filter\_20\_netflow.logstash.conf", "/etc/logstash/elastiflow/conf.d/20\_filter\_30\_ipfix.logstash.conf", "/etc/logstash/elastiflow/conf.d/20\_filter\_40\_sflow.logstash.conf", "/etc/logstash/elastiflow/conf.d/20\_filter\_90\_post\_process.logstash.conf", "/etc/logstash/elastiflow/conf.d/30\_output\_20\_multi.logstash.conf"], :thread=\>"#\<Thread:0x30a5fee5 run\>"}

Has anyone been able to get around this or able to advise how to increase limits in some way?

Thanks & All the BEst

ChIP

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2023, 12:49pm UTC](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803/2 "2023-06-28T12:49:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
