# Ecs compatibiliy warning in logstash

**URL:** <https://discuss.elastic.co/t/ecs-compatibiliy-warning-in-logstash/308263>\
**Category:** Logstash\
**Created:** [June 27, 2022, 2:02pm UTC](https://discuss.elastic.co/t/ecs-compatibiliy-warning-in-logstash/308263 "2022-06-27T14:02:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![NomanLatif](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nomanlatif/32/107288_2.png) [@NomanLatif](https://discuss.elastic.co/u/NomanLatif)\
**Post date:** [June 27, 2022, 2:02pm UTC](https://discuss.elastic.co/t/ecs-compatibiliy-warning-in-logstash/308263/1 "2022-06-27T14:02:02Z")

</div>

We see the following warning in logstash logs

`[2022-06-27T12:23:27,848][WARN][deprecation.logstash.codecs.json][my_pipeline] Relying on default value of `pipeline.ecs\_compatibility`, which may change in a future major release of Logstash. To avoid unexpected changes when upgrading Logstash, please explicitly declare your desired ECS Compatibility mode.`

We found the following thread and set the ecs\_compatibility = disabled at pipeline level  
[[Warning 'Relying on default value of `pipeline.ecs\_compatibility' after updating to logstash 7.16.1](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018)]([https://Warning](https://Warning) ‘Relying on default value of `pipeline.ecs\_compatibility’)

The number of warnings reduced but we still see some warnings. Any idea what we are missing?

Additionally, we see the following error, it seems it tries to look for 2x.json template and that does not exist. Do we need to install something special?

`[2022-06-27T12:23:17,971][ERROR][logstash.outputs.opensearch][my_pipeline] Failed to install template {:message=>"Failed to load default template for OpenSearch v2 with ECS disabled; caused by: #<ArgumentError: Template file '/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-opensearch-1.2.0-java/lib/logstash/outputs/opensearch/templates/ecs-disabled/2x.json' could not be found>", :exception=>RuntimeError, :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-opensearch-1.2.0-java/lib/logstash/outputs/opensearch/template_manager.rb:33:in `load_default_template'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-opensearch-1.2.0-java/lib/logstash/outputs/opensearch/template_manager.rb:21:in `install_template'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-opensearch-1.2.0-java/lib/logstash/outputs/opensearch.rb:412:in `install_template'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-opensearch-1.2.0-java/lib/logstash/outputs/opensearch.rb:247:in `finish_register'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-opensearch-1.2.0-java/lib/logstash/outputs/opensearch.rb:224:in `block in register'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-opensearch-1.2.0-java/lib/logstash/plugin_mixins/opensearch/common.rb:83:in `block in after_successful_connection'"]}`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2022, 2:02pm UTC](https://discuss.elastic.co/t/ecs-compatibiliy-warning-in-logstash/308263/2 "2022-06-27T14:02:02Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![NomanLatif](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nomanlatif/32/107288_2.png) [@NomanLatif](https://discuss.elastic.co/u/NomanLatif)\
**Post date:** [June 28, 2022, 7:53am UTC](https://discuss.elastic.co/t/ecs-compatibiliy-warning-in-logstash/308263/3 "2022-06-28T07:53:14Z")

</div>

Yes, the Template error is opensearch error, I will contact OpenSearch directly. But ecs\_compatibility warning is related to logstash, can anyone help with that?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2022, 7:53am UTC](https://discuss.elastic.co/t/ecs-compatibiliy-warning-in-logstash/308263/4 "2022-06-28T07:53:14Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2022, 7:53am UTC](https://discuss.elastic.co/t/ecs-compatibiliy-warning-in-logstash/308263/5 "2022-07-26T07:53:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
