# Post Upgrading ElasticSearch to 6.8.10 its not receiving data from Logstash(5.6.16)

**URL:** <https://discuss.elastic.co/t/post-upgrading-elasticsearch-to-6-8-10-its-not-receiving-data-from-logstash-5-6-16/240445>\
**Category:** Elasticsearch\
**Created:** [July 9, 2020, 4:15am UTC](https://discuss.elastic.co/t/post-upgrading-elasticsearch-to-6-8-10-its-not-receiving-data-from-logstash-5-6-16/240445 "2020-07-09T04:15:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vsudhaka](https://avatars.discourse-cdn.com/v4/letter/v/8edcca/32.png) [@vsudhaka](https://discuss.elastic.co/u/vsudhaka)\
**Post date:** [July 9, 2020, 4:15am UTC](https://discuss.elastic.co/t/post-upgrading-elasticsearch-to-6-8-10-its-not-receiving-data-from-logstash-5-6-16/240445/1 "2020-07-09T04:15:11Z")

</div>

Hello,

I am new in using ELK stack.

I recently Upgraded Logstash from 5.6.13 -\> 5.6.16 ,ElasticSearch Nodes from 5.6.16 -\> 6.8.10 and Kibana from 5.6.16 -\> 6.8.10.

I did not Upgrade Logstash and FileBeats to version 6.8.10 since it had the Backward compatibility.

Post Upgrade ElasticSearch is not receiving any data from Logstash.Below is the configuration file that have in place.

```auto
**input-beats-logstash**
input {
  beats {
    port => 5044
  }
}

output {
  elasticsearch {
    hosts => ["10.199.202.51:9200", "10.199.202.52:9200", "10.199.202.53:9200"]
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

**input-syslog-logstash**  
input {  
tcp {  
port =\> 1514  
type =\> syslog  
}  
udp {  
port =\> 1514  
type =\> syslog  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["dfsyd1ela01:9200", "dfsyd1ela02:9200", "dfsyd1ela03:9200"]  
stdout { codec =\> rubydebug }  
}  
}

```````````````````````````````````````auto
**output_elasticsearch_syd1**

output {
        elasticsearch {
                hosts => ["10.199.202.51:9200", "10.199.202.52:9200", "10.199.202.53:9200"]
        }

}
``````````````````````````````````````
LogStash Debug Output:- 

root@dfsyd1log01:/etc/logstash/conf.d# /usr/share/logstash/bin/logstash -f logstash-syslog.conf
Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties

Can someone please help in resolving this issue.
```````````````````````````````````````

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 9, 2020, 4:31am UTC](https://discuss.elastic.co/t/post-upgrading-elasticsearch-to-6-8-10-its-not-receiving-data-from-logstash-5-6-16/240445/2 "2020-07-09T04:31:44Z")

</div>

In Elasticsearch 6.x an index can only support a single document type as [document types are being deprecated](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/removal-of-types.html). I see you are specifying document type in your output, and this could cause indexing errors if it took different values or conflicted with an index template.

---

<div class="post-metadata">

**Author:** ![vsudhaka](https://avatars.discourse-cdn.com/v4/letter/v/8edcca/32.png) [@vsudhaka](https://discuss.elastic.co/u/vsudhaka)\
**Post date:** [July 9, 2020, 4:53am UTC](https://discuss.elastic.co/t/post-upgrading-elasticsearch-to-6-8-10-its-not-receiving-data-from-logstash-5-6-16/240445/3 "2020-07-09T04:53:05Z")

</div>

Thanks Chris for your suggestion.

I have now removed the document\_type from the file.Please see below is the latest entries.

Is there a way I can test the ingestion to Elasticsearch nodes or can you suggest any better way of testing the data ingest to Elasticsearch?

```auto
input {
  beats {
    port => 5044
  }
}

output {
  elasticsearch {
    hosts => ["10.199.202.51:9200", "10.199.202.52:9200", "10.199.202.53:9200"]
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2020, 4:53am UTC](https://discuss.elastic.co/t/post-upgrading-elasticsearch-to-6-8-10-its-not-receiving-data-from-logstash-5-6-16/240445/4 "2020-08-06T04:53:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
