# Replace Log4j from 2.11.0 to 2.15.0

**URL:** https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901
**Category:** Logstash
**Created:** [December 15, 2021, 6:15am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901 "2021-12-15T06:15:07Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [December 27, 2021, 12:37pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901/6 "2021-12-27T12:37:08Z")

</div>

No, you can't just replace the jar with a newer version.

Please read the [security announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476/3) about the Log4J exploit, there you will find how to mitigate the issue according to your Logstash/Elasticsearch version.

If what you want to do is not mentioned there, then it is not recommended or testes by elastic.

---

_[View the full topic](https://discuss.elastic.co/t/replace-log4j-from-2-11-0-to-2-15-0/291901)._
