# My exec input plugin does not compatible with ecs

**URL:** <https://discuss.elastic.co/t/my-exec-input-plugin-does-not-compatible-with-ecs/313718>\
**Category:** Logstash\
**Created:** [September 5, 2022, 10:08pm UTC](https://discuss.elastic.co/t/my-exec-input-plugin-does-not-compatible-with-ecs/313718 "2022-09-05T22:08:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MKH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkh/32/100766_2.png) [@MKH](https://discuss.elastic.co/u/MKH)\
**Post date:** [September 5, 2022, 10:08pm UTC](https://discuss.elastic.co/t/my-exec-input-plugin-does-not-compatible-with-ecs/313718/1 "2022-09-05T22:08:27Z")

</div>

Hi,

I am trying to learn ow to use ecs schema within logstash. I use logstash 7.10.0 and input plugin I want to use in my logstash config file is "exec input". I am trying to just follow the documentation guideline [https://www.elastic.co/guide/en/logstash/7.17/plugins-inputs-exec.html#plugins-inputs-exec-ecs\_compatibility](https://www.elastic.co/guide/en/logstash/7.17/plugins-inputs-exec.html#plugins-inputs-exec-ecs_compatibility) for this plugin to learn how to use ecs with it.

I have a config file called exec.conf with the following content:

```auto
input {
    exec {
        command => "echo 'hi--!!!'"
        interval => 10
        ecs_compatibility => v8 
    }
}
output {
    stdout{}
}

```

Regardless of whether I put the line "ecs\_compatibility =\> v8" in my config file or don't, the output I see is:

```auto
{
      "@version" => "1",
    "@timestamp" => 2022-09-05T21:48:16.291Z,
       "message" => "hi--!!!\n",
          "host" => "seroiuts02525",
       "command" => "echo 'hi--!!!'"
}

```

While according to the documentation I should see different outputs when I have ecs\_compatibility enabled and disabled (I think at least I should see the host name like this:

```auto
"host" => {
        "name" => "seroiuts02525"
    },

```

when the ecs\_Compatibility =\> v8 exists in my config file but that is not the case!

I have also tried to enable the ecs\_compatibility in my config/pipeline.yaml file and here is the content of this yaml file regarding this pipeline:

```auto
- pipeline.id: exec-pipeline
   path.config: /repo/emarykh/logstash/logstash-7.10.0/logstash config/config/pipelines/exec.conf
   pipeline.ecs_compatibility: v8 

```

This also does not work and my output remains the same.  
Could someone please help me understand what part I am missing in my configuration?

Thanks,  
Maryam

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 5, 2022, 10:58pm UTC](https://discuss.elastic.co/t/my-exec-input-plugin-does-not-compatible-with-ecs/313718/2 "2022-09-05T22:58:14Z")

</div>

Hi @MKH

> [@MKH](#):
>
> I use logstash 7.10.0

I think your issue is that you're using logstash 7.10.0 but looking at the documentation for 7.17.0.

If you look at the documentation for 7.10.0 the ecs\_compatability does not exist

> **[Exec input plugin | Logstash Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/logstash/7.10/plugins-inputs-exec.html)**

I would recommend upgrading your logstash to a more current version 7.10 is very old.

And technically the docs specify `[host][hostname]` which is what I get with logstasg 7.17 and 8.4

````auto
./bin/logstash -e 'input { stdin { ecs_compatibility => "v8"} } output { stdout {} }' 
....
The stdin plugin is now waiting for input:
[2022-09-05T16:43:01,194][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
test
{
       "message" => "test",
         "event" => {
        "original" => "test\n"
    },
      "@version" => "1",
          "host" => {
        "hostname" => "hyperion.lan"
    },
    "@timestamp" => 2022-09-05T23:43:03.735Z
}
```
````

---

<div class="post-metadata">

**Author:** ![MKH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkh/32/100766_2.png) [@MKH](https://discuss.elastic.co/u/MKH)\
**Post date:** [September 6, 2022, 4:03pm UTC](https://discuss.elastic.co/t/my-exec-input-plugin-does-not-compatible-with-ecs/313718/3 "2022-09-06T16:03:15Z")

</div>

Thank you @stephenb to mention the problem!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2022, 4:03pm UTC](https://discuss.elastic.co/t/my-exec-input-plugin-does-not-compatible-with-ecs/313718/4 "2022-10-04T16:03:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
