# Silence deprecation log without restarting the cluster

**URL:** <https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715>\
**Category:** Elasticsearch\
**Created:** [May 14, 2020, 9:29pm UTC](https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715 "2020-05-14T21:29:28Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Khoa\_Le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khoa_le/32/53602_2.png) [@Khoa\_Le](https://discuss.elastic.co/u/Khoa_Le)\
**Post date:** [May 14, 2020, 9:29pm UTC](https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715/1 "2020-05-14T21:29:28Z")

</div>

Hi,

We had a log4j settings that has set the logging level of `org.elasticsearch.deprecation` to `ERROR` that we set from the `_cluster/settings` endpoint. Ever since we upgraded to 6.8.6, that settings stopped working and the cluster logs a huge number of deprecation warnings. Is there anything that changed from 6.1 to 6.8? We recently upgraded from 6.1.0 to 6.8.0

```auto
    curl -X PUT "http://localhost:9200/_cluster/settings" -H 'Content-Type: application/json' -d'
      {
        "transient": {
          "logger.org.elasticsearch.deprecation": "ERROR"
        }
      }'

```

I think 90% of the warning comes from these 2:  
`Deprecated field [_version_type] used, expected [version_type] instead`  
and  
`Accessing variable [_agg] via [params._agg] from within a scripted metric agg init script is deprecated in favor of using [state].`

Until we make a code change, we'd like to silence the warnings since it's quite noisy and impacts our bill for logging to sumo logic

Thanks,  
Khoa

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 14, 2020, 10:24pm UTC](https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715/2 "2020-05-14T22:24:18Z")

</div>

Hello,  
Your setting was `transient` and it gets reset once you restart all the nodes.

Can you try to do a `GET _cluster/settings` and see if the setting is still there?

If not, please set:

```auto
PUT _cluster/settings
{ "persistent": { "logger.org.elasticsearch.deprecation": "error" } }

```

Be aware this really important when you will move to 7. So please re-enable it as soon as you can.

---

<div class="post-metadata">

**Author:** ![Khoa\_Le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khoa_le/32/53602_2.png) [@Khoa\_Le](https://discuss.elastic.co/u/Khoa_Le)\
**Post date:** [May 14, 2020, 10:41pm UTC](https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715/3 "2020-05-14T22:41:27Z")

</div>

I already tried setting it both as `transient` and `persistent` actually. Our staging environment has it enabled and I just want to silence it in production

---

<div class="post-metadata">

**Author:** ![animageofmine](https://avatars.discourse-cdn.com/v4/letter/a/7feea3/32.png) [@animageofmine](https://discuss.elastic.co/u/animageofmine)\
**Post date:** [May 15, 2020, 6:27pm UTC](https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715/4 "2020-05-15T18:27:38Z")

</div>

Khoa,

Do you mean, the persistent setting does not work as well?

---

<div class="post-metadata">

**Author:** ![Khoa\_Le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khoa_le/32/53602_2.png) [@Khoa\_Le](https://discuss.elastic.co/u/Khoa_Le)\
**Post date:** [May 15, 2020, 7:39pm UTC](https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715/5 "2020-05-15T19:39:42Z")

</div>

No, neither persistent nor transient setting works. At this stage, I think it's probably a Elasticsearch bug

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 15, 2020, 7:56pm UTC](https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715/6 "2020-05-15T19:56:09Z")

</div>

Can you share the output of the Elasticsearch settings with `GET _cluster/settings?include_default`, the `log4j2.properties` and tell if you're running on Docker?

Thanks

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [May 16, 2020, 7:59am UTC](https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715/7 "2020-05-16T07:59:02Z")

</div>

I've tried to reproduce this on 6.8.6. Each time I this against a brand-new 6.8.6 cluster ...

```auto
curl 'http://localhost:9200/_mtermvectors' -H 'Content-type: application/json' --data-binary $'{"docs":[{"_type":"testtype","_version_type":"external","_id":"testing_document","_index":"testidx","version":1}]}'

```

... I see this line in the deprecation log file ...

```auto
[2020-05-16T08:51:11,172][WARN][o.e.d.c.ParseField] [node-0] Deprecated field [_version_type] used, expected [version_type] instead

```

I have confirmed that these logs are indeed correctly suppressed by all three methods mentioned above:

- change `logger.deprecation.level = warn` to `logger.deprecation.level = error` in `log4j2.properties` (and restarting the node)

- setting a transient setting using `curl -XPUT 'http://localhost:9200/_cluster/settings' -H 'Content-type: application/json' --data-binary $'{"transient":{"logger.org.elasticsearch.deprecation":"ERROR"}}'` (no restart needed)

- setting a persistent setting using `curl -XPUT 'http://localhost:9200/_cluster/settings' -H 'Content-type: application/json' --data-binary $'{"persistent":{"logger.org.elasticsearch.deprecation":"ERROR"}}'` (no restart needed)

My best guess at the moment is that these log messages are coming from a different cluster from the one whose config you are adjusting.

---

<div class="post-metadata">

**Author:** ![Khoa\_Le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khoa_le/32/53602_2.png) [@Khoa\_Le](https://discuss.elastic.co/u/Khoa_Le)\
**Post date:** [May 16, 2020, 6:09pm UTC](https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715/8 "2020-05-16T18:09:06Z")

</div>

Thanks David and Luca. The settings was there before and after the upgrade. It's just doesn't seem to do anything. I tried setting it to `ERROR` multiple times but it's not effective.

However, I just found that resetting `"logging.org.elasticsearch.deprecation": null` AND setting it to `ERROR` again from the cluster setting did the job. But it definitely didn't work without setting it to null first. Maybe somehow the rolling restart upgrade invalidate the setting and caused Elasticsearch to not picking up the change from `PUT /_cluster/settings` because it's thinking the changes are the same with what it currently have?

I'll mark this as resolved because my problem has been solved. I've linked the log of `GET _cluster/settings` and my `log4j2.properties`, just in case Elasticsearch team wants to dig deeper

log4j2.properties

> <https://gist.github.com/khoatle/a2bef3749072120e53a1f1c9ad431862>

\_cluster/settings

> <https://gist.github.com/khoatle/c61c94c45c79d8b8bcf69df25ff6c868>

`_cluster/settings?include_default` contains quite a bit sensitive info like IPs and such so I'm not sharing it here. However, if you can tell me what settings you need, I'll fetch it

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 13, 2020, 6:09pm UTC](https://discuss.elastic.co/t/silence-deprecation-log-without-restarting-the-cluster/232715/9 "2020-06-13T18:09:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
