# Elasticsearch filter no longer working in 2.3.1

**URL:** <https://discuss.elastic.co/t/elasticsearch-filter-no-longer-working-in-2-3-1/47908>\
**Category:** Logstash\
**Created:** [April 20, 2016, 1:01pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-no-longer-working-in-2-3-1/47908 "2016-04-20T13:01:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![xdzhou](https://avatars.discourse-cdn.com/v4/letter/x/9de053/32.png) [@xdzhou](https://discuss.elastic.co/u/xdzhou)\
**Post date:** [April 20, 2016, 1:01pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-no-longer-working-in-2-3-1/47908/1 "2016-04-20T13:01:53Z")

</div>

I was using logstash-all-plugins-2.2.0 package before and now I am switching to logstash-all-plugins-2.3.1, the same configuration goes against a ES 2.3.1 works using 2.2.0 version, but not 2.3.1 version.

The elasticsearch filter configuration is straightfoward

elasticsearch {  
hosts =\> ["192.168.3.3:9200"]  
query =\> "MCC:242 AND MNC:1 AND LAC:12201 AND CELL:7157"  
fields =\> ["path", "ppp"]  
}

Using 2.2.0 package, I am able to get result, but with 2.3.1 I am getting following error

:error=\>#NoMethodError: undefined method `start\_with?' for nil:NilClass, :level=\>:warn, :file=\>"logstash/filters/elasticsearch.rb", :line=\>"99", :method=\>"filter"}

Any clue? I see change log regarding dependency updates, maybe not fully tested?

---

<div class="post-metadata">

**Author:** ![xdzhou](https://avatars.discourse-cdn.com/v4/letter/x/9de053/32.png) [@xdzhou](https://discuss.elastic.co/u/xdzhou)\
**Post date:** [April 24, 2016, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-filter-no-longer-working-in-2-3-1/47908/2 "2016-04-24T08:35:01Z")

</div>

And now I am having another similar problem with translate plugin. I have been using translate filter using logstash 2.3.1 and it was working fine. like

translate {  
field =\> "xxxx"  
dictionary\_path =\> "/yyyy/zzzz.csv"  
destination =\> "wwww"  
}

The configuration works in logstash 2.3.1, but when running with logstash 2.2.0, I got this error

The error reported is:  
LogStash::Filters::Translate: Bad Syntax in dictionary file /yyyy/zzzz.csv

Combining this issue and the issue above, I cannot run using either version which has both elasticsearch and translate filter. 😖

As I did not see any coding change in these two plugin but dependency changes, I will appreciate any help that can pointing me to the direction to solve this problem.

---

<div class="post-metadata">

**Author:** ![Andrew\_Shved](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@Andrew\_Shved](https://discuss.elastic.co/u/Andrew_Shved)\
**Post date:** [May 17, 2016, 9:18pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-no-longer-working-in-2-3-1/47908/3 "2016-05-17T21:18:52Z")

</div>

did you get anywhere with this. I am looking to downgrade to 2.2 just to have plug in working. Critical to my PoC but if thats not fixed in the future I dont want to build the dependency on unsupported plugin ☹

---

<div class="post-metadata">

**Author:** ![xdzhou](https://avatars.discourse-cdn.com/v4/letter/x/9de053/32.png) [@xdzhou](https://discuss.elastic.co/u/xdzhou)\
**Post date:** [May 22, 2016, 12:14pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-no-longer-working-in-2-3-1/47908/4 "2016-05-22T12:14:52Z")

</div>

I end up by looking at the source code and even try to enhance it. There is a pull request [https://github.com/logstash-plugins/logstash-filter-elasticsearch/pull/31](https://github.com/logstash-plugins/logstash-filter-elasticsearch/pull/31) that enhance it with the index support and talk about a problem with specifying the fields option, the documentation is wrong. it should be like this

fields =\> [["@timestamp", "started"] ]

or fields =\> { "a" =\> "b" "c" =\> "d" } worked for me also.

---

<div class="post-metadata">

**Author:** ![Andrew\_Shved](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@Andrew\_Shved](https://discuss.elastic.co/u/Andrew_Shved)\
**Post date:** [May 22, 2016, 2:16pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-no-longer-working-in-2-3-1/47908/5 "2016-05-22T14:16:28Z")

</div>

thanks that did the trick the documentation was wrong...

---

<div class="post-metadata">

**Author:** ![goldsky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/goldsky/32/40178_2.png) [@goldsky](https://discuss.elastic.co/u/goldsky)\
**Post date:** [July 15, 2016, 3:14pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-no-longer-working-in-2-3-1/47908/6 "2016-07-15T15:14:40Z")

</div>

Thanks a lot,  
I spend several hours trying to understand why:

fields =\> [["data"] ]

doesn't work...till I saw your post...first element of array is a source field name from old, but second one are destination:

fields =\> [["src\_doc\_fieldname","desc\_doc\_fieldname"] ]

or this are more clear then:

fields =\> { "src" =\> "desc" }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:47am UTC](https://discuss.elastic.co/t/elasticsearch-filter-no-longer-working-in-2-3-1/47908/7 "2017-07-06T04:47:49Z")

</div>


