# Replace Log4j from 2.x to 2.17.0 or later

**URL:** https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897
**Category:** Elasticsearch
**Created:** [December 24, 2021, 1:28pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897 "2021-12-24T13:28:07Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![marisubu](https://avatars.discourse-cdn.com/v4/letter/m/ecae2f/32.png) [@marisubu](https://discuss.elastic.co/u/marisubu)
#### Post date: [December 24, 2021, 1:28pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897/1 "2021-12-24T13:28:07Z")

</div>

Our oldest products includes Elastic stack versions 5.2, 6.2.2 and 7.10.2. We're in situation that we can not perform elastic versions uplift to the latest/fixed versions.

Can we replace Log4j 2.x versions with 2.17.x or later for Elasticsearch and logstash in the version - 5.2, 6.2.2 and 7.10.2.

Please suggest.

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [December 24, 2021, 2:17pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897/2 "2021-12-24T14:17:14Z")

</div>

No, you can't just replace de library for a newer version.

All the recommendations regarding the Log4shell exploit are in the pinned [security announcement](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476), there you will find instructions to mitigate this in different versions.

---

<div class="post-metadata">

### Author: ![marisubu](https://avatars.discourse-cdn.com/v4/letter/m/ecae2f/32.png) [@marisubu](https://discuss.elastic.co/u/marisubu)
#### Post date: [January 13, 2022, 3:08am UTC](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897/3 "2022-01-13T03:08:27Z")

</div>

Thank you! , Just for my understanding, why is log4j jar replacement not recommended by elastic?

---

<div class="post-metadata">

### Author: ![marisubu](https://avatars.discourse-cdn.com/v4/letter/m/ecae2f/32.png) [@marisubu](https://discuss.elastic.co/u/marisubu)
#### Post date: [January 24, 2022, 1:01pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897/4 "2022-01-24T13:01:39Z")

</div>

Hi Team,

Please help us with following information

- Technical information on why the Elastic community does not recommend directly replacing jars.

- Apache v2 license applies to both Elastic versions mentioned and Log4j 2.17.1. Does Elastic community anticipate any license violations if we replace the log4j 2.x version with Log2.17.1 jar ( from [Apache Downloads](https://www.apache.org/dyn/closer.lua/logging/log4j/2.17.1/apache-log4j-2.17.1-bin.tar.gz)) on the Elastic stack components versions ( 5.2, 6.2.2 and OSS distribution of 7.10.2 ) after validating our use cases ?

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [January 24, 2022, 1:16pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897/5 "2022-01-24T13:16:53Z")

</div>

> [@marisubu](#):
>
> - Technical information on why the Elastic community does not recommend directly replacing jars.

It's not tested or supported and it's entirely possible that it just doesn't work. The announcement to which @leandrojmp linked contains advice and recommendations for what to do with older versions, although of course the primary recommendation is to address any blockers and upgrade to supported versions as a matter of urgency.

> [@marisubu](#):
>
> Does Elastic community anticipate any license violations

We can't offer legal advice. You will need to consult your own lawyer to answer this question.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 21, 2022, 1:17pm UTC](https://discuss.elastic.co/t/replace-log4j-from-2-x-to-2-17-0-or-later/292897/6 "2022-02-21T13:17:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
