# Kibana Fleet error after upgrading Elastic Cloud to 7.11

**URL:** https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969
**Category:** Kibana
**Created:** [February 11, 2021, 8:53am UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969 "2021-02-11T08:53:24Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)
#### Post date: [February 11, 2021, 8:53am UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969/1 "2021-02-11T08:53:24Z")

</div>

Hi,

We get the following error when opening fleet page after upgrading from 7.10.2 to 7.11:

```auto
Unable to initialize Fleet

[illegal_argument_exception] updating component template [logs-endpoint.events.file-mappings] results in invalid composable template [logs-endpoint.events.file] after templates are merged response from /_component_template/logs-endpoint.events.file-mappings: {"error":{"root_cause":[{"type":"illegal_argument_exception","reason":"updating component template [logs-endpoint.events.file-mappings] results in invalid composable template [logs-endpoint.events.file] after templates are merged"}],"type":"illegal_argument_exception","reason":"updating component template [logs-endpoint.events.file-mappings] results in invalid composable template [logs-endpoint.events.file] after templates are merged","caused_by":{"type":"illegal_argument_exception","reason":"template [logs-endpoint.events.file] has alias and data stream definitions"}},"status":400}

```

How to solve the issue?

Regards,  
Nugroho

---

<div class="post-metadata">

### Author: ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)
#### Post date: [February 11, 2021, 10:35am UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969/2 "2021-02-11T10:35:49Z")

</div>

Adding more information. Sometimes I get this error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d5553eaf7428b815f1cd0981c79d6021991c241.png)

When I refresh I get a different error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/8/58dc512ab5a63a15fb5c024fcb61c0640c5273bf.png)

---

<div class="post-metadata">

### Author: ![skh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skh/32/38637_2.png) [@skh](https://discuss.elastic.co/u/skh)
#### Post date: [February 11, 2021, 11:03am UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969/3 "2021-02-11T11:03:54Z")

</div>

Hi @nugroho-expereo ,

this sounds a lot like a problem we fixed during development in [[Fleet] Do not defined aliases inside datastream template by nchaulet · Pull Request #89512 · elastic/kibana · GitHub](https://github.com/elastic/kibana/pull/89512) -- are you using the release, or an earlier snapshot?

---

<div class="post-metadata">

### Author: ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)
#### Post date: [February 11, 2021, 11:09am UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969/4 "2021-02-11T11:09:22Z")

</div>

Hi @skh I am not sure I understand your question but we used Upgrade link in the Elastic cloud managed service to upgrade from 7.10.2 to 7.11.0.

---

<div class="post-metadata">

### Author: ![skh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skh/32/38637_2.png) [@skh](https://discuss.elastic.co/u/skh)
#### Post date: [February 11, 2021, 11:14am UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969/5 "2021-02-11T11:14:52Z")

</div>

Hi @nugroho-expereo this answers my question, thank you! We're looking into it.

---

<div class="post-metadata">

### Author: ![rudolf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rudolf/32/51200_2.png) [@rudolf](https://discuss.elastic.co/u/rudolf)
#### Post date: [February 11, 2021, 11:28am UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969/6 "2021-02-11T11:28:05Z")

</div>

@nugroho-expereo Please open a support ticket from Elastic cloud, that will help us better investigate this and find the root cause faster.

---

<div class="post-metadata">

### Author: ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)
#### Post date: [February 11, 2021, 1:35pm UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969/7 "2021-02-11T13:35:59Z")

</div>

I opened a similar issue here, didn't find this post before unfortunately.

=\> [[Fleet] Upgrade to 7.11 failed · Issue #90984 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/90984)

---

<div class="post-metadata">

### Author: ![skh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skh/32/38637_2.png) [@skh](https://discuss.elastic.co/u/skh)
#### Post date: [February 11, 2021, 2:41pm UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969/8 "2021-02-11T14:41:34Z")

</div>

We're working on a fix for this issue.

In the mean time, there is a workaround:

Open the Fleet UI and pick the problematic index template from the error message:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/3/1/3129542cd1790e2d1fb578ddd57a310eee803a98.png)

The problematic template here is `logs-endpoint.alerts` -- pick the **composable** template, not the **component** template from the error message.

In Kibana dev tools, read that template with

`GET _index_template/logs-endpoint.alerts`

From the first and only search result, copy out the content of the `index_template` property and paste it into a separate text file.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/1/4/14823db6e3e7cb8137ca3258f96075234c639a85.png)

Remove the offending `aliases` property

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/6/860a60b7ed01f7cdf75dddff6fc6a345e1d9f969.png)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/0/80be25253ad03f26be14f2204af2a06f2b61cd42.png)

Copy the changed JSON content and write it back to ES in kibana dev tools with

 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d5ee301b3cecae440dc37a4d64747988c494fd5.png)

Use the Autoindent feature in dev tools so you’re sure the JSON has balanced brackets.

Go back to the Fleet UI, which will show the same error but for another composable template. Repeat these steps until the Fleet UI comes up normally again.

---

<div class="post-metadata">

### Author: ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)
#### Post date: [February 11, 2021, 3:23pm UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969/9 "2021-02-11T15:23:50Z")

</div>

Thanks. It works now after performing the workaround.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 11, 2021, 3:24pm UTC](https://discuss.elastic.co/t/kibana-fleet-error-after-upgrading-elastic-cloud-to-7-11/263969/10 "2021-03-11T15:24:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
