# Errors After Filebeat Upgrade to 6.3.1

**URL:** https://discuss.elastic.co/t/errors-after-filebeat-upgrade-to-6-3-1/142568
**Category:** Logstash
**Created:** [August 1, 2018, 12:28pm UTC](https://discuss.elastic.co/t/errors-after-filebeat-upgrade-to-6-3-1/142568 "2018-08-01T12:28:22Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Or\_Arnon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/or_arnon/32/43677_2.png) [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)
#### Post date: [August 1, 2018, 12:28pm UTC](https://discuss.elastic.co/t/errors-after-filebeat-upgrade-to-6-3-1/142568/1 "2018-08-01T12:28:22Z")

</div>

Hi,

After upgrading our Filebeat to 6.3.1, we get error on our Logstash servers that consume these logs from Kafka and insert to Elasticsearch (5.3)

```auto
[2018-08-01T09:19:04,028][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"tag-mediation-2018.08.01", :_type=>"logs", :_routing=>nil}, 2018-08-01T09:19:03.185Z {"name":"tagmediation-i-0c6dadf01c99ec637.eu-west-1.production"} %{message}], :response=>{"index"=>{"_index"=>"tag-mediation-2018.08.01", "_type"=>"logs", "_id"=>"AWT0yJcsvdiggc-2mDWo", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [host]", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:656"}}}}}

```

---

<div class="post-metadata">

### Author: ![tgaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgaudin/32/32583_2.png) [@tgaudin](https://discuss.elastic.co/u/tgaudin)
#### Post date: [August 1, 2018, 12:33pm UTC](https://discuss.elastic.co/t/errors-after-filebeat-upgrade-to-6-3-1/142568/2 "2018-08-01T12:33:30Z")

</div>

If you come from Filebeat \<= 6.2, then it looks like it's caused by this breaking change: [https://www.elastic.co/guide/en/beats/libbeat/6.3/breaking-changes-6.3.html#breaking-changes-mapping-conflict](https://www.elastic.co/guide/en/beats/libbeat/6.3/breaking-changes-6.3.html#breaking-changes-mapping-conflict), but I might be wrong.

---

<div class="post-metadata">

### Author: ![Or\_Arnon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/or_arnon/32/43677_2.png) [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)
#### Post date: [August 6, 2018, 10:17am UTC](https://discuss.elastic.co/t/errors-after-filebeat-upgrade-to-6-3-1/142568/3 "2018-08-06T10:17:25Z")

</div>

Hi,

Actually, We came from Filebeat 5.2.2. And from what I understand, the upgrade was suppose to be seamless.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 3, 2018, 10:17am UTC](https://discuss.elastic.co/t/errors-after-filebeat-upgrade-to-6-3-1/142568/4 "2018-09-03T10:17:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
