# Logstash not start after upgrade to new version

**URL:** <https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849>\
**Category:** Logstash\
**Created:** [December 14, 2021, 5:48pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849 "2021-12-14T17:48:29Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexander\_Popov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexander_popov/32/7154_2.png) [@Alexander\_Popov](https://discuss.elastic.co/u/Alexander_Popov)\
**Post date:** [December 14, 2021, 5:48pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/1 "2021-12-14T17:48:29Z")

</div>

was 7.10.2, upgrade to 7.16.1  
but it not start:

```auto
21-12-14T17:31:17,721][ERROR][logstash.javapipeline][main] Pipeline error {:pipeline_id=>"main", :exception=>#<LogStash::ConfigurationError: Could not connect to a compatible version of Elasticsearch>, :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:247:in `block in healthcheck!'", "org/jruby/RubyHash.java:1415:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:240:in `healthcheck!'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:374:in `update_urls'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:89:in `update_initial_urls'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:83:in `start'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/outputs/elasticsearch/http_client.rb:359:in `build_pool'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/outputs/elasticsearch/http_client.rb:63:in `initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/outputs/elasticsearch/http_client_builder.rb:106:in `create_http_client'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/outputs/elasticsearch/http_client_builder.rb:102:in `build'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/plugin_mixins/elasticsearch/common.rb:34:in `build_client'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.2.3-java/lib/logstash/outputs/elasticsearch.rb:275:in `register'", "org/logstash/config/ir/compiler/OutputStrategyExt.java:131:in `register'", "org/logstash/config/ir/compiler/AbstractOutputDelegatorExt.java:68:in `register'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:232:in `block in register_plugins'", "org/jruby/RubyArray.java:1821:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:231:in `register_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:589:in `maybe_setup_out_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:244:in `start_workers'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:189:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:141:in `block in start'"], "pipeline.sources"=>["/usr/share/logstash/pipeline/logstash.conf"], :thread=>"#<Thread:0x37e693f2 run>"}

```

config is pretty simple

```auto
input {
  beats {
    port => 5044
    client_inactivity_timeout => 3600
  }
}

output {

  elasticsearch {
    hosts => ""
    user=> ""
    ilm_enabled => false
    password=> ""
    ssl => true
    ssl_certificate_verification => false
  }
  
}

```

Elasticsearch is 7.10( aws opensearch)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 14, 2021, 5:52pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/2 "2021-12-14T17:52:04Z")

</div>

> [@Alexander\_Popov](#):
>
> Elasticsearch is 7.10( aws opensearch)

That is the issue, from version 7.13+ the `elasticsearch` output plugin in Logstash checks if it is an Elasticsearch distributed by Elastic, which is not your case.

You should install the third party `opensearch` output plugin or downgrade Logstash, you won't be able to use the `elasticsearch` output plugin with Opensearch in this version.

For more information you should check the Opensearch foruns, as Opensearch is not supported here.

---

<div class="post-metadata">

**Author:** ![blaklabz1](https://avatars.discourse-cdn.com/v4/letter/b/f17d59/32.png) [@blaklabz1](https://discuss.elastic.co/u/blaklabz1)\
**Post date:** [December 15, 2021, 7:18pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/3 "2021-12-15T19:18:39Z")

</div>

Hey i'm running into this issue as well. I was previously using logstash-oss 7.10.2 with opendistro 1.13.2. This ran fine, but when i upgrade due to the log4j issue, the OSS version is now telling me it doesn't like ES. When I tried the opensearch-output-logstash, I still ran into the version problem. The 7.10.2 version worked, does this version have the log4j vulnerability?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [December 15, 2021, 7:40pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/4 "2021-12-15T19:40:07Z")

</div>

> When I tried the opensearch-output-logstash, I still ran into the version problem

AFAICT, it is not _quite_ a drop-in replacement. To use it, you will also need to modify your pipeline to use the `opensearch` output plugin.

---

<div class="post-metadata">

**Author:** ![blaklabz1](https://avatars.discourse-cdn.com/v4/letter/b/f17d59/32.png) [@blaklabz1](https://discuss.elastic.co/u/blaklabz1)\
**Post date:** [December 15, 2021, 7:51pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/5 "2021-12-15T19:51:38Z")

</div>

hey you have a link on that configuration? Thanks for the heads up.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [December 15, 2021, 7:56pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/6 "2021-12-15T19:56:20Z")

</div>

> hey you have a link on that configuration?

Not exactly, as I have never used it. It is a fork of our `elasticsearch` output plugin, and largely has the same options that were available at the time of fork, plus whatever else they have added.

Given the `elasticsearch` output plugin is invoked with something like:

```auto
output {
  elasticsearch {
    # ... plugin options
  }
}

```

Invoking the `opensearch` output plugin would therefore be something like:

```auto
output {
  opensearch {
    # ... plugin options
  }
}

```

---

<div class="post-metadata">

**Author:** ![blaklabz1](https://avatars.discourse-cdn.com/v4/letter/b/f17d59/32.png) [@blaklabz1](https://discuss.elastic.co/u/blaklabz1)\
**Post date:** [December 15, 2021, 8:30pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/7 "2021-12-15T20:30:18Z")

</div>

lol Yaauie, yeah i just figure this out, thanks to your hint! Works like a charm now.

---

<div class="post-metadata">

**Author:** ![abb](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@abb](https://discuss.elastic.co/u/abb)\
**Post date:** [December 23, 2021, 8:12am UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/8 "2021-12-23T08:12:04Z")

</div>

@blaklabz1 @yaauie @Alexander_Popov @leandrojmp  
We are also facing the similar issue. We have used docker to install plugin as below

```auto
FROM docker.elastic.co/logstash/logstash:${logstash_version}
RUN bin/logstash-plugin install logstash-output-datadog_metrics
RUN bin/logstash-plugin install ?? <Want to install Opensearch plugin>

```

I didn't find any opensearch plugin [here](https://www.elastic.co/guide/en/logstash/current/output-plugins.html)

Could someone tell me how to install the logstash opensearch plugin for ES opendistro 1.13.3.

I tried changing my output plugin from Elasticsearch to opensearch as below but did not work. Still it showed the pipeline failed to load

```auto
output {
  opensearch {
`.......` 
  }
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 23, 2021, 1:10pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/9 "2021-12-23T13:10:58Z")

</div>

Opensearch and Opendistro are not supported here.

You won' t find the opensearch output plugin listed on the Elastic documentation page, it is an third party plugin, it is not made by elastic.

You should check in the [opensearch](https://opensearch.org/docs/latest/clients/logstash/index/) site or look for a opensearch community.

---

<div class="post-metadata">

**Author:** ![ni3rpawar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ni3rpawar/32/99704_2.png) [@ni3rpawar](https://discuss.elastic.co/u/ni3rpawar)\
**Post date:** [December 30, 2021, 4:48pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/10 "2021-12-30T16:48:35Z")

</div>

I had the same issues as above, while going through the lots of posts/blogs and figured out and fixed log4j vulnerabilities issue with my latest opendistro Elasticsearch image with logstash-0ss image, I am running this in K8s,

this is my dockerfile for Elasticsearch of opendistro,

```auto
FROM amazon/opendistro-for-elasticsearch:1.13.3
RUN ./bin/elasticsearch-plugin install --batch repository-azure

```

this is for opensearch logstash-oss image,

```auto
FROM opensearchproject/logstash-oss-with-opensearch-output-plugin:7.16.2
RUN bin/logstash-plugin install logstash-output-opsgenie
RUN bin/logstash-plugin install logstash-output-opensearch

```

and here is the details about output opensearch plugin,

```auto
        output {
          opensearch {
            hosts => "${ELASTICSEARCH_HOST}"
            user => "${ELASTICSEARCH_USER}"
            password => "${ELASTICSEARCH_PASSWORD}"
            cacert => "/usr/share/logstash/certs/ca.crt"
            ssl => true
            manage_template => false
            index => "dlq-%{+YYYY.MM.dd}"
          }

```

whosoever is facing issues of logstash-oss image from "[docker.elastic.co/logstash/logstash-oss:7.8.1](http://docker.elastic.co/logstash/logstash-oss:7.8.1)" and trying to make it compatible with Elasticsearch image of "amazon/opendistro-for-Elasticsearch:1.13.3", above code snippet should resolve it.

I was getting errors in logstash about "ilm\_enabled =\> false" parameter in output plugin, I had to remove that.

Hope above things will help and save others time....I have learned and fixed my issues by reading above discussion threads, thank you guys 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 27, 2022, 4:48pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849/11 "2022-01-27T16:48:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
