# Logstash index issue after 5.x to 6.2 upgrade

**URL:** <https://discuss.elastic.co/t/logstash-index-issue-after-5-x-to-6-2-upgrade/119118>\
**Category:** Logstash\
**Created:** [February 8, 2018, 8:23pm UTC](https://discuss.elastic.co/t/logstash-index-issue-after-5-x-to-6-2-upgrade/119118 "2018-02-08T20:23:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [February 8, 2018, 8:23pm UTC](https://discuss.elastic.co/t/logstash-index-issue-after-5-x-to-6-2-upgrade/119118/1 "2018-02-08T20:23:03Z")

</div>

Hello, all.

Yesterday, I upgraded my Elastic stack from version 5.x to 6.2, and today, my logstash (and filebeat) indices no longer work. Here's some output from elasticsearch.log:

[2018-02-08T00:03:29,150][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-2018.02.08", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x6297d867], :response=\>{"index"=\>{"\_index"=\>"logstash-2018.02.08", "\_type"=\>"doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Failed to parse mapping [_default_]: [include\_in\_all] is not allowed for indices created on or after version 6.0.0 as [\_all] is deprecated. As a replacement, you can use an [copy\_to] on mapping fields to create your own catch all field.", "caused\_by"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"[include\_in\_all] is not allowed for indices created on or after version 6.0.0 as [\_all] is deprecated. As a replacement, you can use an [copy\_to] on mapping fields to create your own catch all field."}}}}}

I've googled extensively, but can't seem to come up with a solution. I would appreciate your (very detailed) help in getting back to good.

Many thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 8, 2018, 8:26pm UTC](https://discuss.elastic.co/t/logstash-index-issue-after-5-x-to-6-2-upgrade/119118/2 "2018-02-08T20:26:16Z")

</div>

This is really more of an Elasticsearch question. Your problem just happens to show up when using Logstash and Filebeat.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [February 8, 2018, 8:26pm UTC](https://discuss.elastic.co/t/logstash-index-issue-after-5-x-to-6-2-upgrade/119118/3 "2018-02-08T20:26:58Z")

</div>

Thanks, Magnus. I'll post there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2018, 8:27pm UTC](https://discuss.elastic.co/t/logstash-index-issue-after-5-x-to-6-2-upgrade/119118/4 "2018-03-08T20:27:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
