# Pipeline.ecs\_compatibility WARN logs

**URL:** <https://discuss.elastic.co/t/pipeline-ecs-compatibility-warn-logs/292164>\
**Category:** Logstash\
**Tags:** ecs-elastic-common-schema\
**Created:** [December 16, 2021, 1:49pm UTC](https://discuss.elastic.co/t/pipeline-ecs-compatibility-warn-logs/292164 "2021-12-16T13:49:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![adizalmanovich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adizalmanovich/32/99121_2.png) [@adizalmanovich](https://discuss.elastic.co/u/adizalmanovich)\
**Post date:** [December 16, 2021, 1:49pm UTC](https://discuss.elastic.co/t/pipeline-ecs-compatibility-warn-logs/292164/1 "2021-12-16T13:49:58Z")

</div>

I have some question. I upgraded my ELK to 7.16.1 due to a Log4j2 security issue.  
In my logstash configuration, we are using to get input from Azure EventHub and Kubernetes cluster.  
after upgraded my ELK I am getting huge amount of WARN logs in logstash about:  
`[WARN][deprecation.logstash.codecs.plain][main][192d4ff28a8bbed04078f9f42501af310049e890b5122bc26451fd524fa2cd78] Relying on default value of `pipeline.ecs\_compatibility`, which may change in a future major release of Logstash. To avoid unexpected changes when upgrading Logstash, please explicitly declare your desired ECS Compatibility mode.`  
In the internet I just found that I need to add: `ecs_compatibility => disabled` in each output section.  
for example:  
`if "nginx-geoip" in [tags] {`  
` elasticsearch {`  
` hosts => ["` `elasticsearch-client.es` `.svc.cluster.local:9200"]`  
` manage_template => true`  
` index => "logstash-nginx-geoip-%{+YYYY.MM.dd}" `  
` ecs_compatibility => disabled`  
` }`  
` }`  
I added it but I still get this WARN every sec. Does someone maybe know how to resolve/ignore from those WARNs?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [December 16, 2021, 3:27pm UTC](https://discuss.elastic.co/t/pipeline-ecs-compatibility-warn-logs/292164/2 "2021-12-16T15:27:34Z")

</div>

The log message occurs during plugin startup, for any plugin attempting to determine what mode it should be initialized in (not just output plugins), when neither the plugin or the pipeline that it is run in declare what mode it should be run in. To silence the deprecation warning for an entire pipeline, you can address it by setting the pipeline-level setting. The value `disabled` locks in the current default behaviour.

> [@Warning 'Relying on default value of \`pipeline.ecs\_compatibility' after updating to logstash 7.16.1](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018/3):
>
> When the option isn't specified for an individual plugin, it checks the pipeline-level setting. When the pipeline-level setting is also not specified, you get this warning (not an error). If you want to lock in the current behaviour for all plugins in a pipeline, add pipeline.ecs\_compatibility: disabled to its definition in your config/pipelines.yml. If you want to do so globally, for all pipelines, add pipeline.ecs\_compatibility: disabled to your config/logstash.yml.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2022, 3:27pm UTC](https://discuss.elastic.co/t/pipeline-ecs-compatibility-warn-logs/292164/3 "2022-01-13T15:27:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
