# Filebeat no more working - Can not index event (status=400)

**URL:** https://discuss.elastic.co/t/filebeat-no-more-working-can-not-index-event-status-400/61227
**Category:** Beats
**Tags:** filebeat
**Created:** [September 22, 2016, 9:56am UTC](https://discuss.elastic.co/t/filebeat-no-more-working-can-not-index-event-status-400/61227 "2016-09-22T09:56:07Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![toasti](https://avatars.discourse-cdn.com/v4/letter/t/b2d939/32.png) [@toasti](https://discuss.elastic.co/u/toasti)
#### Post date: [September 22, 2016, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-no-more-working-can-not-index-event-status-400/61227/6 "2016-09-22T12:56:47Z")

</div>

I solved it, hope that is correct now:

Based on this post from Andrew I did the same with filebeat, also using the filebeat.yml from version 1.3.1:

> [@Issue shipping Winlogbeat 5.x to Elasticsearch 2.x](https://discuss.elastic.co/t/issue-shipping-winlogbeat-5-x-to-elasticsearch-2-x/47301/6):
>
> It looks like you are using the Winlogbeat 5.0.0-alpha1 with Elasticsearch 1.x or 2.x? There is an incompatibility with the winlogbeat.template.json index template provided in Winlogbeat v5 and earlier versions of Elasticsearch because the template uses the text keyword that was introduced in ES v5. To continue to use Winlogbeat 5.x with ES 1.x or 2.x you'll need to grab the index template provided in Winlogbeat 1.x and install it to ES. Cleanup: Stop Winlogbeat. Delete the .winlogbeat.yml r…

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-no-more-working-can-not-index-event-status-400/61227)._
