# Logstash pkg update results log prasing stopped

**URL:** <https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542>\
**Category:** Logstash\
**Created:** [January 5, 2023, 12:15pm UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542 "2023-01-05T12:15:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dilipssn](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@Dilipssn](https://discuss.elastic.co/u/Dilipssn)\
**Post date:** [January 5, 2023, 12:15pm UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542/1 "2023-01-05T12:15:09Z")

</div>

Hello Team,

We have logstash to push the logs from one server to other, where all the traps are collected. Through which we plot graphs in "Grafana". The port number in which logs parsing is "7546".

until "logstash-7.16.3-1.x86\_64" it was worked without any issues and I have updated with "logstash-8.5.3-1.x86\_64", then it stopped parsing the logs.

could you please help us to fix the issue?

Below are our configurations.

[root@localhost logstash]# ls -ltrh  
total 48K  
-rw------- 1 root root 1.7K Nov 30 08:40 startup.options  
-rw-r--r-- 1 root root 285 Nov 30 08:40 pipelines.yml  
-rw-r--r-- 1 root root 342 Nov 30 08:40 logstash-sample.conf  
-rw-r--r-- 1 root root 7.3K Nov 30 08:40 log4j2.properties  
-rw-r--r-- 1 root root 1.9K Nov 30 08:40 jvm.options  
-rw-r--r-- 1 root root 15K Jan 3 09:07 logstash.yml  
-rw-r--r-- 1 root root 300 Jan 3 09:07 monit\_alert.yml  
drwxr-xr-x 2 root root 4.0K Jan 5 10:59 conf.d

[root@localhost logstash]# cat logstash.yml |grep -v "#"  
path.data: /var/lib/logstash

path.logs: /var/log/logstash

Below are the ports connections displayed, and they are looking good.

[root@localhost logstash]# netstat -tulnp | grep 7546  
tcp6 0 0 172.20.61.15:7546 :::\* LISTEN 975750/java  
udp 0 0 172.20.61.15:7546 0.0.0.0:\* 975750/java  
[root@localhost logstash]#

[root@localhost-2~]# netstat -tulnp | grep 7546  
tcp 0 0 172.20.61.7:7546 0.0.0.0:\* LISTEN 50233/haproxy  
[root@localhost-2 ~]#

---

<div class="post-metadata">

**Author:** ![Dilipssn](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@Dilipssn](https://discuss.elastic.co/u/Dilipssn)\
**Post date:** [January 5, 2023, 12:36pm UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542/2 "2023-01-05T12:36:55Z")

</div>

we have below "deprecation" log. Does this got any effect that the issue that am facing now ?

[2023-01-05T00:01:14,032][WARN][deprecation.logstash.codecs.line][main][37a9313707e5221038d742efc461ec902fd1d7138c0a83d0998e19b6e8d4abb4] Relying on default value of `pipeline.ecs_compatibility`, which may change in a future major release of Logstash. To avoid unexpected changes when upgrading Logstash, please explicitly declare your desired ECS Compatibility mode.  
[2023-01-05T00:01:14,039][WARN][deprecation.logstash.codecs.line][main][37a9313707e5221038d742efc461ec902fd1d7138c0a83d0998e19b6e8d4abb4] Relying on default value of `pipeline.ecs_compatibility`, which may change in a future major release of Logstash. To avoid unexpected changes when upgrading Logstash, please explicitly declare your desired ECS Compatibility mode.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 5, 2023, 12:44pm UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542/3 "2023-01-05T12:44:14Z")

</div>

> [@Dilipssn](#):
>
> Does this got any effect that the issue that am facing now ?

This may be the cause since the name of some of the fields that logstash generate are different now.

This is mentioned as a [breaking change](https://www.elastic.co/guide/en/logstash/current/breaking-8.0.html#bc-ecs-compatibility) in the docs.

Add the following line in your `logstash.yml` and restart logstash to see if it works as before.

```auto
pipeline.ecs_compatibility: disabled

```

---

<div class="post-metadata">

**Author:** ![Dilipssn](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@Dilipssn](https://discuss.elastic.co/u/Dilipssn)\
**Post date:** [January 5, 2023, 1:54pm UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542/4 "2023-01-05T13:54:25Z")

</div>

Is there a way to customize it in RPM itself, as this file "logstash.yml" extracted from RPM.

But can I able to "src.rpm" ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 5, 2023, 2:24pm UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542/5 "2023-01-05T14:24:08Z")

</div>

> [@Dilipssn](#):
>
> Is there a way to customize it in RPM itself, as this file "logstash.yml" extracted from RPM.

You do not need that, if you edit the `logstash.yml` any update you do will not override it.

---

<div class="post-metadata">

**Author:** ![Dilipssn](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@Dilipssn](https://discuss.elastic.co/u/Dilipssn)\
**Post date:** [January 6, 2023, 3:52am UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542/6 "2023-01-06T03:52:52Z")

</div>

In-fact, you are correct. but, we are an engineering team and we ship the RPMs with minimal ISO and customized them with our own third-party applications (one of them is Logstash) to customers. We can't ask them to do these changes after the ISO is installed (ISO will have the logstash RPM). Hence, it's important for us to fix it before shipping the product to the customer.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 6, 2023, 1:19pm UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542/7 "2023-01-06T13:19:12Z")

</div>

You have a custom RPM for Logstash, is that what you mean? It is not clear

In any case, your issue is probably caused by the default configuration of `pipeline.ecs_compatibility`, you need to test if changing it to `disabled` in `logstash.yml` wil solve.

If this solve, you need to have this config in `logstash.yml`, how you will manage that is entirely dependent on your infrastructure and is out of the scope of the forum.

Another option is to have the `pipeline.ecs_compatibility: disabled` setting in each pipeline in `pipelines.yml`, which I understand your customers can edit.

---

<div class="post-metadata">

**Author:** ![Dilipssn](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@Dilipssn](https://discuss.elastic.co/u/Dilipssn)\
**Post date:** [January 9, 2023, 1:57am UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542/8 "2023-01-09T01:57:50Z")

</div>

Custom RPM, I meant that we download the logstash RPM and build it with the ISO image. In this ISO we'll have many other 3rd party tools like logstash, zookeeper, etc...

we use "\*.src.rpm" file and using rpmbuild we customize the RPM with changes like what in in this particular case we need to add an entry in the config file "logstash.yml".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2023, 1:58am UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542/9 "2023-02-06T01:58:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
