# \[SOLVED\] Index issues after upgrade from 5.x to 6.2

**URL:** <https://discuss.elastic.co/t/solved-index-issues-after-upgrade-from-5-x-to-6-2/119119>\
**Category:** Elasticsearch\
**Created:** [February 8, 2018, 8:29pm UTC](https://discuss.elastic.co/t/solved-index-issues-after-upgrade-from-5-x-to-6-2/119119 "2018-02-08T20:29:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [February 8, 2018, 8:29pm UTC](https://discuss.elastic.co/t/solved-index-issues-after-upgrade-from-5-x-to-6-2/119119/1 "2018-02-08T20:29:23Z")

</div>

Hello, all.

Yesterday, I upgraded my Elastic stack from version 5.x to 6.2, and today, my logstash and filebeat indices no longer work. Here's some output from elasticsearch.log:

[2018-02-08T00:03:29,150][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-2018.02.08", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x6297d867], :response=\>{"index"=\>{"\_index"=\>"logstash-2018.02.08", "\_type"=\>"doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Failed to parse mapping [default]: [include\_in\_all] is not allowed for indices created on or after version 6.0.0 as [\_all] is deprecated. As a replacement, you can use an [copy\_to] on mapping fields to create your own catch all field.", "caused\_by"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"[include\_in\_all] is not allowed for indices created on or after version 6.0.0 as [\_all] is deprecated. As a replacement, you can use an [copy\_to] on mapping fields to create your own catch all field."}}}}}

I've googled extensively, but can't seem to come up with a solution. I would appreciate your (very detailed) help in getting back to good.

Many thanks.

---

<div class="post-metadata">

**Author:** ![Enis](https://avatars.discourse-cdn.com/v4/letter/e/ea666f/32.png) [@Enis](https://discuss.elastic.co/u/Enis)\
**Post date:** [February 9, 2018, 11:51am UTC](https://discuss.elastic.co/t/solved-index-issues-after-upgrade-from-5-x-to-6-2/119119/2 "2018-02-09T11:51:49Z")

</div>

Hey,

I had the same problem and the solution for this problem is written in this post:

> [@Failed to parse mapping for index](https://discuss.elastic.co/t/failed-to-parse-mapping-for-index/110102/4):
>
> Get the current one using the [index template API](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/indices-templates.html) and update it. You can the push it back into the cluster using the same API. If you are using the default Logstash template, you can just upload the [standard 6.0 template](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es6x.json) and overwrite the existing one.

I have deleted my saved logstash template and added the standard logstash template like mentioned.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [February 9, 2018, 2:23pm UTC](https://discuss.elastic.co/t/solved-index-issues-after-upgrade-from-5-x-to-6-2/119119/3 "2018-02-09T14:23:14Z")

</div>

Enis,

Thanks so much for the reply. I'm happy to say that your suggestion worked for logstash! Very much appreciated!

I still have the same problem for Filebeat, though. Any idea about how I deal with that?

Diggy

---

<div class="post-metadata">

**Author:** ![Enis](https://avatars.discourse-cdn.com/v4/letter/e/ea666f/32.png) [@Enis](https://discuss.elastic.co/u/Enis)\
**Post date:** [February 9, 2018, 3:03pm UTC](https://discuss.elastic.co/t/solved-index-issues-after-upgrade-from-5-x-to-6-2/119119/4 "2018-02-09T15:03:41Z")

</div>

Sorry. I had that problem only with Logstash. For Filebeat it could be perhaps a separate template if you use Filebeat directly to write to Elasticsearch. Which version of Filebeat are you using and did you update your config file?

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [February 9, 2018, 4:49pm UTC](https://discuss.elastic.co/t/solved-index-issues-after-upgrade-from-5-x-to-6-2/119119/5 "2018-02-09T16:49:15Z")

</div>

Well, I think I've made some progress re: Filebeat, but I don't know what it is that I did. Filebeat log for one of many servers is now appearing in Kibana, but it's only the apache-access log. /var/log and /var/secure log information are not appearing. Nor are logs from any other server running Filebeat. Can anyone help?

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [February 9, 2018, 10:20pm UTC](https://discuss.elastic.co/t/solved-index-issues-after-upgrade-from-5-x-to-6-2/119119/6 "2018-02-09T22:20:35Z")

</div>

Well, solved mostly. I followed Enis' suggestion for the Logstash part, and that worked. For Filebeat, I had to upgrade to version 6.2 on one host, generate filebeat.template.json on that host and get it over to my Elastic host, remove the filebeat index, and add the index with the filebeat.template.json. I'm still struggling to get Filebeat working on my Windows hosts, but will ask about that in the Filebeat list.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2018, 10:20pm UTC](https://discuss.elastic.co/t/solved-index-issues-after-upgrade-from-5-x-to-6-2/119119/7 "2018-03-09T22:20:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
