# Fix log4j ：upgrade ES version OR replace log4j.jar to 2.17.2

**URL:** https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786
**Category:** Elasticsearch
**Created:** [April 20, 2022, 9:29am UTC](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786 "2022-04-20T09:29:57Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![qiuxb](https://avatars.discourse-cdn.com/v4/letter/q/48db29/32.png) [@qiuxb](https://discuss.elastic.co/u/qiuxb)
#### Post date: [April 20, 2022, 9:29am UTC](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786/1 "2022-04-20T09:29:58Z")

</div>

At present, we have more than 500 Elasticsearch clusters, with thousands of nodes. The Elasticsearch versions are 6.3.2, 7.2 and 7.4. In order to solve the log4j vulnerability, if you choose to upgrade the Elasticsearch version on a large scale, it will affect the online business. The cost is relatively high. I have recently referred to other repair methods, such as replacing the log4j jar version with 2.17.2. Which method is currently considered? give me some advice

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [April 20, 2022, 9:33am UTC](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786/2 "2022-04-20T09:33:02Z")

</div>

Have a look at [this thread](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897).

---

<div class="post-metadata">

### Author: ![qiuxb](https://avatars.discourse-cdn.com/v4/letter/q/48db29/32.png) [@qiuxb](https://discuss.elastic.co/u/qiuxb)
#### Post date: [April 20, 2022, 9:49am UTC](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786/3 "2022-04-20T09:49:08Z")

</div>

Thank you, if I can't use the solution of replacing the jar package,  
can I refer to this solution ：

> [@Elasticsearch 5.0.0-5.6.10 and 6.0.0-6.3.2: Log4j CVE-2021-44228, CVE-2021-45046 remediation](https://discuss.elastic.co/t/elasticsearch-5-0-0-5-6-10-and-6-0-0-6-3-2-log4j-cve-2021-44228-cve-2021-45046-remediation/292054):
>
> Note — If you are not running Elasticsearch 5.0.0-5.6.10 or 6.0.0-6.3.2, these instructions do not apply. Please follow the guidance in the [main announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476). Instructions for removing JndiLookup from the log4j-core JAR file​ These instructions only apply to users running Elasticsearch versions between 5.0.0 and 5.6.10 (inclusive) or between 6.0.0 and 6.3.2 (inclusive). These must not be used in other versions of Elasticsearch as there are safer, supported remediations (or no remediation is ne…

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [April 20, 2022, 10:04am UTC](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786/4 "2022-04-20T10:04:03Z")

</div>

It seems like that would apply to your 6.3.2 clusters but not the 7.x ones.

---

<div class="post-metadata">

### Author: ![qiuxb](https://avatars.discourse-cdn.com/v4/letter/q/48db29/32.png) [@qiuxb](https://discuss.elastic.co/u/qiuxb)
#### Post date: [April 21, 2022, 7:48am UTC](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786/5 "2022-04-21T07:48:05Z")

</div>

Yes, only handles Elasticsearch version 6.3.2, excluding 7.x

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 21, 2022, 7:48am UTC](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786/6 "2022-04-21T07:48:05Z")

</div>

Elasticsearch version 6.3 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 19, 2022, 7:49am UTC](https://discuss.elastic.co/t/fix-log4j-upgrade-es-version-or-replace-log4j-jar-to-2-17-2/302786/7 "2022-05-19T07:49:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
