# Logstash not inserted data into elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [February 5, 2023, 1:42pm UTC](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737 "2023-02-05T13:42:47Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohanss08](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohanss08/32/82297_2.png) [@mohanss08](https://discuss.elastic.co/u/mohanss08)\
**Post date:** [February 5, 2023, 1:42pm UTC](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737/1 "2023-02-05T13:42:47Z")

</div>

Hello Team,

I had `Elasticsearch, Logstash and Kibana v7.16.2` with `xpack security based login enabled`, Yesterday i had upgraded my ELK versions to `8.6.1` using my docker-compose file.

**Current problem:** My logstash fetched the data but not inserted in to elasticsearch. But no error shown in my ELK containers.

my `logstash.conf` as follows.

```auto
input {
	beats {
		port => 5044
	}

	tcp {
		port => 5000
	}
 
  file {
    path => "/usr/share/logstash/pipeline/*.csv"
    start_position => "beginning"
    sincedb_path => "/usr/share/logstash/pipeline/sincedb.txt"
  }
}
filter {
  csv {
      separator => ","
      columns => ["build_date", "build_start_time", "build_end_time", "build_duration", "build_requester", "fullname", "build_id", "build_conf", "build_status", "build_site"]
  }
}
output {
   elasticsearch {
     action => "index"
     hosts => "http://elasticsearch:9200"
     index => "employee-data"
     user => "elastic"
     password => "changeme"
     document_id => "%{build_id}"
      }
stdout {}
}

```

It was working fine with my previous `ELK version - 7.16.2`, So what could the issue with my current version & configurations?

Any help on this will be helpful.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 5, 2023, 6:36pm UTC](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737/2 "2023-02-05T18:36:17Z")

</div>

> [@mohanss08](#):
>
> `sincedb_path => "/usr/share/logstash/pipeline/sincedb.txt"`

AFAIK nothing reported on the latest LS version.  
Maybe is already read the file. Use ruby debugger: `stdout { codec => rubydebug{} }`

---

<div class="post-metadata">

**Author:** ![mohanss08](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohanss08/32/82297_2.png) [@mohanss08](https://discuss.elastic.co/u/mohanss08)\
**Post date:** [February 6, 2023, 5:18am UTC](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737/3 "2023-02-06T05:18:46Z")

</div>

@Rios - I have added `stdout { codec => rubydebug{} }` then removed all the entries from `sincedb_path => "/usr/share/logstash/pipeline/sincedb.txt"` and tried, but still i can't see the data in elasticsearch that i have loaded into my logstash.

I can see the below warnings and errors in my logstash container now.

```auto
[WARN][logstash.outputs.elasticsearch][main][13ed313a5675abd23c078edd33a0a3c4be86d627339fd3bf53181d4183411c94] Could not index event to Elasticsearch. status: 400, action: ["index", {:_id=>"61975163", :_index=>"employee-data",

"error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [host] of type [text] in document with id '61975163'. Preview of field's value: '{name=8cb532a93e4e}'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:416"}}}}

"error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [host] of type [text] in document with id '61959101'. Preview of field's value: '{name=8cb532a93e4e}'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:419"}}}}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 6, 2023, 4:21pm UTC](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737/4 "2023-02-06T16:21:43Z")

</div>

Are you using somewhere the filed: host?  
Can you try with next setting in logstash.yml or if you are using pipelines in pipelines.yml or directly in plugin setting.  
`pipeline.ecs_compatibility: disabled`

Default value v8. Click [here for more details](https://www.elastic.co/guide/en/logstash/current/ecs-ls.html).

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 6, 2023, 6:14pm UTC](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737/5 "2023-02-06T18:14:19Z")

</div>

> [@Rios](#):
>
> Are you using somewhere the filed: host?

This is probably the issue, the `file` input [adds](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-ecs) the `host` field.

On version 7 it was added into the field `host`, on version 8 ecs compatibility is enabled by default and the value of the hostname is added into the `host.name` field, which will lead to mapping issues.

This is a [breaking change](https://www.elastic.co/guide/en/logstash/master/breaking-8.0.html#bc-ecs-compatibility) from 7.X to 8.X.

Just add the setting suggested and it should work.

---

<div class="post-metadata">

**Author:** ![mohanss08](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohanss08/32/82297_2.png) [@mohanss08](https://discuss.elastic.co/u/mohanss08)\
**Post date:** [February 7, 2023, 4:16am UTC](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737/6 "2023-02-07T04:16:48Z")

</div>

Hi @Rios and @leandrojmp - Have updated `pipeline.ecs_compatibility: disabled` settings and i could see the data in elasticsearch.

Thanks a lot for the support.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 7, 2023, 6:45am UTC](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737/7 "2023-02-07T06:45:24Z")

</div>

Long live the king and the Elastic team.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2023, 6:45am UTC](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737/8 "2023-03-07T06:45:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
