# Indexing Error?

**URL:** <https://community.graylog.org/t/indexing-error/3395>\
**Category:** Graylog Central (peer support)\
**Created:** [December 5, 2017, 5:28pm UTC](https://community.graylog.org/t/indexing-error/3395 "2017-12-05T17:28:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ThomasPowers](https://avatars.discourse-cdn.com/v4/letter/t/bbe5ce/32.png) [@ThomasPowers](https://community.graylog.org/u/ThomasPowers)\
**Post date:** [December 5, 2017, 5:28pm UTC](https://community.graylog.org/t/indexing-error/3395/1 "2017-12-05T17:28:23Z")

</div>

Hello Graylog Friends!!

OK…so I have a larger install, storing about 1500 events a second. We have our indices set to 1 day and purge after 30 count. This is a fresh build of Graylog on Ubuntu 16.04, 24 GB ram, 8 cores of proc, 6 TB of storage, running Graylog 2.3.1

We are seeing this error in the logs, but I’m not sure what to do about it.

```
**{"type":"illegal_argument_exception","reason":"Limit of total fields [1000] in index [graylog_82] has been exceeded"}**

```

All insight is appreciated

Thanks

TP

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [December 6, 2017, 7:25am UTC](https://community.graylog.org/t/indexing-error/3395/2 "2017-12-06T07:25:18Z")

</div>

you created to many fields and you should limit the fields you write per index to something that is lower than 1000.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [December 6, 2017, 9:21am UTC](https://community.graylog.org/t/indexing-error/3395/3 "2017-12-06T09:21:23Z")

</div>

For reference:

- [https://www.elastic.co/guide/en/elasticsearch/reference/5.6/mapping.html#mapping-limit-settings](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/mapping.html#mapping-limit-settings)
- [https://discuss.elastic.co/t/total-fields-limit-setting/53004](https://discuss.elastic.co/t/total-fields-limit-setting/53004)

---

<div class="post-metadata">

**Author:** ![ThomasPowers](https://avatars.discourse-cdn.com/v4/letter/t/bbe5ce/32.png) [@ThomasPowers](https://community.graylog.org/u/ThomasPowers)\
**Post date:** [December 8, 2017, 5:17pm UTC](https://community.graylog.org/t/indexing-error/3395/4 "2017-12-08T17:17:02Z")

</div>

OK…but I haven’t added any fields. This is just windows machines, running to a single GELF input, being sent via nxlog.

How does it have too many fields?

TP

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [December 9, 2017, 10:17am UTC](https://community.graylog.org/t/indexing-error/3395/5 "2017-12-09T10:17:23Z")

</div>

The Windows EventLog sends structured messages, so if you have many different events in the Windows EventLog with vastly different field names and don’t consolidate these fields in Graylog (e. g. via the processing pipelines), you can get 1000+ different field names.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [December 23, 2017, 10:17am UTC](https://community.graylog.org/t/indexing-error/3395/6 "2017-12-23T10:17:41Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
