# Info on Logstash 2.3.4 and Elasticsearch 2.1.0 compatibility

**URL:** <https://discuss.elastic.co/t/info-on-logstash-2-3-4-and-elasticsearch-2-1-0-compatibility/58649>\
**Category:** Elasticsearch\
**Created:** [August 23, 2016, 6:20am UTC](https://discuss.elastic.co/t/info-on-logstash-2-3-4-and-elasticsearch-2-1-0-compatibility/58649 "2016-08-23T06:20:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharath3185](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@sharath3185](https://discuss.elastic.co/u/sharath3185)\
**Post date:** [August 23, 2016, 6:20am UTC](https://discuss.elastic.co/t/info-on-logstash-2-3-4-and-elasticsearch-2-1-0-compatibility/58649/1 "2016-08-23T06:20:20Z")

</div>

I am working with logstash 2.3.4 and elasticsearch 2.1.0 versions for my project where I am doing some performance testing for indexing the data into elasticsearch through logstash.

I am working on a search feature on indexed data, for which I am indexing logfiles as documents.  
We have around 82000 logfiles which constitutes to around 1.4 G in size in total. one logfile is indexed as one document where logfile data is stored as string in a field.

Example of a document:

{  
"\_index" : "global\_test",  
"\_type" : "logsearch",  
"\_id" : "log1",  
"\_score" : 1.0,  
"\_source":{"@timestamp":"2016-08-12T07:26:35.571Z","type":"GLOBAL\_LOG","logdata":"logfile contents goes here", "logfile":"logname here","logfilepath":"path/to/log/file",}  
}  
We are testing the compression ratio for all the 1.4 G of data and below is the analysis

curl [http://127.0.0.1:9200/\_cat/indices?v](http://127.0.0.1:9200/_cat/indices?v)

health status index pri rep docs.count docs.deleted store.size pri.store.size  
**yellow open globallogs\_test 5 1 82443 0 715.5mb 715.5mb**

As above with logstash version 2.3.4(latest version) and Elasticsearch version 2.1.0, 1.4 G of data has been compressed to 715.5 MB.

**Last week I upgraded Elasticsearch to latest version 2.3.5 and ran the same test again with same data. This time 1.4 G of data was compressed to 881.5 MB.**

So I am planning to revert my Elasticsearch version back to 2.1.0 to achieve the greater compression as above i.e. 715.5 MB.

**My question is, will there be any compatibility issues if we use logstash 2.3.4(latest) along with elasticsearch version 2.1.0 (older version)?**

**Also, why the compression ratio varied if we used latest elasticsearch version?**

Config file just for your reference:

input  
{  
file  
{  
path =\> ["path/to/logs"]  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
type =\> "GLOBAL\_LOG"  
max\_open\_files =\> 10000  
close\_older =\> 300  
ignore\_older =\> 0  
}  
}

filter  
{  
if [type] == "GLOBAL\_LOG"{

```
 multiline {
       pattern => "/.*./gm"
       negate => true
       what => "previous"
    }

 ruby
    {
        code => "
        event['logfile'] = event['path'].split('/').last
        event['logfilepath'] = event['path'].strip
        "
    }

mutate
    {
        add_field => ["logdata", "%{message}"]
        remove_field => ["@version", "path", "host", tags, "message"]
    }

```

}

```
}

```

output  
{  
if [type] == "GLOBAL\_LOG"  
{  
stdout  
{  
codec =\> rubydebug  
}  
elasticsearch  
{  
template\_name =\> "template\_name"  
manage\_template =\> true  
template =\> "/etc/logstash/mapping/template\_name.json"  
hosts =\> "127.0.0.1:9200"  
index =\> "index\_name"  
document\_type =\> "logsearch"  
document\_id =\> "%{[logfilepath]}"  
}  
}  
}

Request your quick response on this.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 23, 2016, 7:08am UTC](https://discuss.elastic.co/t/info-on-logstash-2-3-4-and-elasticsearch-2-1-0-compatibility/58649/2 "2016-08-23T07:08:42Z")

</div>

> My question is, will there be any compatibility issues if we use logstash 2.3.4(latest) along with elasticsearch version 2.1.0 (older version)?

No. See [Support Matrix | Elastic](https://www.elastic.co/support/matrix#show_compatibility).

> So I am planning to revert my Elasticsearch version back to 2.1.0 to achieve the greater compression as above i.e. 715.5 MB.

Running an older ES version to save 165 MB of disk space doesn't make much sense to me.

> Also, why the compression ratio varied if we used latest elasticsearch version?

Different Lucene, probably.

---

<div class="post-metadata">

**Author:** ![sharath3185](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@sharath3185](https://discuss.elastic.co/u/sharath3185)\
**Post date:** [August 23, 2016, 7:23am UTC](https://discuss.elastic.co/t/info-on-logstash-2-3-4-and-elasticsearch-2-1-0-compatibility/58649/3 "2016-08-23T07:23:21Z")

</div>

Thanks Magnus for the quick response.

> Running an older ES version to save 165 MB of disk space doesn't make much sense to me.

For this, 1.4 GB is only the sample data. In production environment, it might go well beyond 100 GB. In that case, more disk space will be saved if I use ES 2.1.0 is my thought.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 23, 2016, 7:28am UTC](https://discuss.elastic.co/t/info-on-logstash-2-3-4-and-elasticsearch-2-1-0-compatibility/58649/4 "2016-08-23T07:28:46Z")

</div>

100 GB, 1 TB, whatever. I still don't think running an old ES release to save 10% disk space is a very good idea.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 23, 2016, 7:39am UTC](https://discuss.elastic.co/t/info-on-logstash-2-3-4-and-elasticsearch-2-1-0-compatibility/58649/5 "2016-08-23T07:39:05Z")

</div>

Are you using [best\_compression](https://www.elastic.co/guide/en/elasticsearch/reference/2.3/index-modules.html#_static_index_settings) for your indices?

---

<div class="post-metadata">

**Author:** ![sharath3185](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@sharath3185](https://discuss.elastic.co/u/sharath3185)\
**Post date:** [August 23, 2016, 7:48am UTC](https://discuss.elastic.co/t/info-on-logstash-2-3-4-and-elasticsearch-2-1-0-compatibility/58649/6 "2016-08-23T07:48:12Z")

</div>

Yes. I do as below in my elasticsearch.yml

**index.codec: best\_compression**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:25pm UTC](https://discuss.elastic.co/t/info-on-logstash-2-3-4-and-elasticsearch-2-1-0-compatibility/58649/7 "2017-07-05T22:25:58Z")

</div>


