# Logstash Configuration file in 8.2

**URL:** <https://discuss.elastic.co/t/logstash-configuration-file-in-8-2/306019>\
**Category:** Logstash\
**Created:** [May 31, 2022, 9:31am UTC](https://discuss.elastic.co/t/logstash-configuration-file-in-8-2/306019 "2022-05-31T09:31:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![KunwarAkanksha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kunwarakanksha/32/79144_2.png) [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Post date:** [May 31, 2022, 9:31am UTC](https://discuss.elastic.co/t/logstash-configuration-file-in-8-2/306019/1 "2022-05-31T09:31:42Z")

</div>

After upgrading the ELK stack to 8.2 my logstash configuration file where i have defined the filters for logstash-filter-geoip have changed some key names , like victimASN.as\_org is now coming as victimASN.as.organization.name . Though from kibana I can give the alternate name to the keys but still my previous visualization have stopped working and showing the error as :

_Could not locate that data view (id: 55cac390-014e-11ea-95b2-770559be5cdf), [click here to re-create it]_

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 31, 2022, 2:20pm UTC](https://discuss.elastic.co/t/logstash-configuration-file-in-8-2/306019/2 "2022-05-31T14:20:31Z")

</div>

> In Logstash 8, all plugins are run in ECS compatibility v8 mode by default.

You can set on level:

1. Plugin  
filter {  
geoip {  
source =\> "[host][ip]"  
**ecs\_compatibility =\> disabled**  
}  
}

2. Pipeline:  
pipeline.ecs\_compatibility: v8

You can set to values: `disabled`, `v1` or `v8`

---

<div class="post-metadata">

**Author:** ![KunwarAkanksha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kunwarakanksha/32/79144_2.png) [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Post date:** [June 1, 2022, 6:07am UTC](https://discuss.elastic.co/t/logstash-configuration-file-in-8-2/306019/3 "2022-06-01T06:07:10Z")

</div>

Thanks, doing this has solved the problem. Though I have set it from the logstash.yml file (pipeline. ecs\_compatibility =\> disabled)

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [June 1, 2022, 7:58am UTC](https://discuss.elastic.co/t/logstash-configuration-file-in-8-2/306019/4 "2022-06-01T07:58:04Z")

</div>

`pipeline. ecs_compatibility => disabled` will set value as default to all in .conf file  
`geoip { source => "[host][ip]" ecs_compatibility => disabled }` will set only for that param

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2022, 7:58am UTC](https://discuss.elastic.co/t/logstash-configuration-file-in-8-2/306019/5 "2022-06-29T07:58:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
