# Logstash Pipeline not eligible for data streams

**URL:** <https://discuss.elastic.co/t/logstash-pipeline-not-eligible-for-data-streams/359458>\
**Category:** Logstash\
**Created:** [May 14, 2024, 12:33pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-eligible-for-data-streams/359458 "2024-05-14T12:33:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 14, 2024, 12:33pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-eligible-for-data-streams/359458/1 "2024-05-14T12:33:11Z")

</div>

Hello,

I'm using Winlogbeat and filebeat to ingest logs into ELK, the beats agents output is logstash.

I've setup according this process order:

- Point winlogbeat to Elasticsearch
- run setup `winlogbeat.exe setup -e`
- Start winlogbeat ... observe data getting written
- Stop winlogbeat
- Point winlogbeat to logstash
- Start logstash with the config below:

```auto
input {
        beats {
                port => 5044
        }
}

output {
  if [@metadata][pipeline] {
    elasticsearch {
        hosts => "elasticsearch:9200"
        manage_template => false
        index => "%{[@metadata][beat]}-%{[@metadata][version]}"
        action => "create"
        pipeline => "%{[@metadata][pipeline]}"
        user => "logstash_internal"
        password => "${LOGSTASH_INTERNAL_PASSWORD}"
    }
  } else {
     elasticsearch {
        hosts => "elasticsearch:9200"
        manage_template => false
        index => "%{[@metadata][beat]}-%{[@metadata][version]}"
        action => "create"
        user => "logstash_internal"
        password => "${LOGSTASH_INTERNAL_PASSWORD}"
    }
  }
}

```

But I have theses errors logs:

```auto
logstash | [2024-05-14T14:12:44,480][INFO][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//elasticsearch:9200"]}
logstash | [2024-05-14T14:12:44,487][INFO][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://logstash_internal:xxxxxx@elasticsearch:9200/]}}
logstash | [2024-05-14T14:12:44,501][WARN][logstash.outputs.elasticsearch][main] Restored connection to ES instance {:url=>"http://logstash_internal:xxxxxx@elasticsearch:9200/"}
logstash | [2024-05-14T14:12:44,502][INFO][logstash.outputs.elasticsearch][main] Elasticsearch version determined (8.13.2) {:es_version=>8}
logstash | [2024-05-14T14:12:44,502][WARN][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>8}
logstash | [2024-05-14T14:12:44,510][INFO][logstash.outputs.elasticsearch][main] Not eligible for data streams because config contains one or more settings that are not compatible with data streams: {"index"=>"%{[@metadata][beat]}-%{[@metadata][version]}"}
logstash | [2024-05-14T14:12:44,510][INFO][logstash.outputs.elasticsearch][main] Data streams auto configuration (`data_stream => auto` or unset) resolved to `false`

```

If I look on Kibana in Stack Management, I can see the data stream and Index getting data incoming:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/d/1dc195fdffe1c951b179334719ec0aaf1bf738bf.png)

Should I just ignore the said error ?

```auto
logstash | [2024-05-14T14:12:44,510][INFO][logstash.outputs.elasticsearch][main] Not eligible for data streams because config contains one or more settings that are not compatible with data streams: {"index"=>"%{[@metadata][beat]}-%{[@metadata][version]}"}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 14, 2024, 12:53pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-eligible-for-data-streams/359458/2 "2024-05-14T12:53:54Z")

</div>

> [@s0p4L1n3](#):
>
> But I have theses errors logs

There are no errors in the logs you shared, they are `INFO` and `WARN` logs, you can ignore them.

---

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 14, 2024, 12:58pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-eligible-for-data-streams/359458/3 "2024-05-14T12:58:31Z")

</div>

Alright, thank you 👍
