# Logstash ECS Compatiblity Issues

**URL:** <https://discuss.elastic.co/t/logstash-ecs-compatiblity-issues/304260>\
**Category:** Logstash\
**Created:** [May 9, 2022, 2:01pm UTC](https://discuss.elastic.co/t/logstash-ecs-compatiblity-issues/304260 "2022-05-09T14:01:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![teamomni](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@teamomni](https://discuss.elastic.co/u/teamomni)\
**Post date:** [May 9, 2022, 2:01pm UTC](https://discuss.elastic.co/t/logstash-ecs-compatiblity-issues/304260/1 "2022-05-09T14:01:44Z")

</div>

We have moved our Logstash indices to data stream recently but are having issues with the geopoints. As a result, the geofencing for everything including the Elastic agents are broken. At first there was the error:

> Pipeline error {:pipeline\_id=\>"network\_logs", :exception=\>#\<LogStash::ConfigurationError: GeoIP Filter in ECS-Compatiblity mode requires a `target` when `source` is not an `ip` sub-field, eg. [client][ip]\>

But ECS compatibility has been disabled for the two IP variables while the rest is v8 compatible:

```auto
filter {
  if [source.ip] =~ /^192.168.1.*$/ {
    mutate {
      add_field => ["source.geo.location", "41.12, -71.34"]
    }
    geoip {
      source => "destination.ip"
      ecs_compatibility => disabled
    }
    mutate {
      add_field => ["destination.geo.location", "%{[geoip][latitude]}, %{[geoip][longitude]}" ]
    }
  }
  if [destination.ip] =~ /^192.168.1.*$/ {
    mutate {
      add_field => ["destination.geo.location", "41.12, -71.34"]
    }
    geoip {
      source => "source.ip"
      ecs_compatibility => disabled
    }
    mutate {
      add_field => ["source.geo.location", "%{[geoip][latitude]}, %{[geoip][longitude]}" ]
    }
  }
}

```

Is it possible to edit the filter so that the source.ip and destination.ip would be compliant with ECS without the ‘target’ error so that the map works properly again?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2022, 2:16pm UTC](https://discuss.elastic.co/t/logstash-ecs-compatiblity-issues/304260/2 "2022-05-09T14:16:16Z")

</div>

Do all your fields really have periods in their names? Should [destination.ip] be [destination][ip]? Likewise should source.geo.location be [source][geo][location]?

The default template for an Elasticsearch output makes [geoip][location] a geo\_point. For any other field you will need a template that sets the type.

---

<div class="post-metadata">

**Author:** ![teamomni](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@teamomni](https://discuss.elastic.co/u/teamomni)\
**Post date:** [May 9, 2022, 2:23pm UTC](https://discuss.elastic.co/t/logstash-ecs-compatiblity-issues/304260/3 "2022-05-09T14:23:59Z")

</div>

Those fields do have periods rather than brackets, they have been that way for years, but I will test your way and see if that fixes the problem.

---

<div class="post-metadata">

**Author:** ![teamomni](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@teamomni](https://discuss.elastic.co/u/teamomni)\
**Post date:** [May 9, 2022, 2:44pm UTC](https://discuss.elastic.co/t/logstash-ecs-compatiblity-issues/304260/4 "2022-05-09T14:44:07Z")

</div>

Thank you @Badger , that did fix the ECS compatibility issue.

Another question, the agents are supplying POINT geo locations, but the logs coming in with the “lat,lon” strings are only keywords. Do I need to just reindex the entire logs-\* or will the string remain only a keyword?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2022, 2:50pm UTC](https://discuss.elastic.co/t/logstash-ecs-compatiblity-issues/304260/5 "2022-05-09T14:50:11Z")

</div>

If you indexed data without a template that made those fields geo\_points then you will need to reindex them _with_ such a template.

---

<div class="post-metadata">

**Author:** ![teamomni](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@teamomni](https://discuss.elastic.co/u/teamomni)\
**Post date:** [May 9, 2022, 2:54pm UTC](https://discuss.elastic.co/t/logstash-ecs-compatiblity-issues/304260/6 "2022-05-09T14:54:16Z")

</div>

That's what I thought, thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2022, 2:55pm UTC](https://discuss.elastic.co/t/logstash-ecs-compatiblity-issues/304260/7 "2022-06-06T14:55:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
