# Update of ELK stack

**URL:** https://discuss.elastic.co/t/update-of-elk-stack/98156
**Category:** Elasticsearch
**Created:** [August 24, 2017, 5:21am UTC](https://discuss.elastic.co/t/update-of-elk-stack/98156 "2017-08-24T05:21:50Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)
#### Post date: [August 24, 2017, 5:21am UTC](https://discuss.elastic.co/t/update-of-elk-stack/98156/1 "2017-08-24T05:21:50Z")

</div>

Hi,  
I am using below versions of ELK  
Elasticsearch 1.5  
Logstash 1.5.3  
Kibana 4.0.0  
filebeat 1.2.1

I am planning to upgrade ELK and FB versions . Please suggest me which one should I go for now?  
What new features I can get in latest one? Though I am going through breaking changes documntation, a quick expert comment will help.

br,  
Sunil

---

<div class="post-metadata">

### Author: ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)
#### Post date: [August 24, 2017, 7:34am UTC](https://discuss.elastic.co/t/update-of-elk-stack/98156/2 "2017-08-24T07:34:59Z")

</div>

Hi Sunil,

Here's the upgrade path I chose a few months ago from about the same version you are running now. My use case is log shipping and analysis.

I use puppet as a configuration management system and I had the _luxury_ of getting new hardware for the new setup which meant that I did not need to deal with backing up Elasticsearch indices and restoring them to the new setup.

I am also running three clusters (testing, staging and production) which gives me a bit of tolerance when trying new features...

The new versioning makes life much easier so I would just choose the latest stable release (which should be 5.5.2 at the moment) for all of the Elastic products. I pushed 5.5.2 to testing yesterday and will upgrade staging today. With a configuration management system the minor version upgrades are quite easy.

Configuration changes I had to do for the upgrade from pre version 5

- Logstash GROK filters needed rewriting
- Elasticsearch will need to bind to an IP other than localhost to cluster
- I had not noticed that I was running an old JAVA version so had to update that ("We recommend installing Java version 1.8.0\_131 or later")

As far as I remember those were the major things in addition to anything that is mentioned in the _breaking changes documentation_

I made sure to use the same input settings in Logstash so I could point DNS at the new setup when everything was ready. Then I worked through anything that was still coming in to the old setup, one by one, to restart services that had cached the old DNS data.

I was not really looking for any specific new features so can't comment on that 🙂

-AB

---

<div class="post-metadata">

### Author: ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)
#### Post date: [August 24, 2017, 8:22am UTC](https://discuss.elastic.co/t/update-of-elk-stack/98156/3 "2017-08-24T08:22:07Z")

</div>

Hi,  
Thank you for precise reply.  
However, please elaborate this?

> [@A\_B](#):
>
> Logstash GROK filters needed rewriting

Does that mean, there are some different syntaxes?  
Cant I just copy the same old configuration to new installation?

br,  
Sunil

---

<div class="post-metadata">

### Author: ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)
#### Post date: [August 24, 2017, 8:46am UTC](https://discuss.elastic.co/t/update-of-elk-stack/98156/4 "2017-08-24T08:46:25Z")

</div>

Can't remember exactly anymore... Something changed with _multiline_ and maybe some other plugins like GeoIP as well. It was just a matter of testing the config agains the new Logstash.

There also seems to be a new Grok debugger [Debugging Grok Expressions | Kibana User Guide [5.5] | Elastic](https://www.elastic.co/guide/en/kibana/5.5/xpack-grokdebugger.html)

I think I used this as well [Running Logstash from the Command Line | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html)  
(does not help with Grok patterns though)

> -t, --config.test\_and\_exit  
> Check configuration for valid syntax and then exit. Note that grok patterns are not checked for correctness with this flag. Logstash can read multiple config files from a directory. If you combine this flag with --log.level=debug, Logstash will log the combined config file, annotating each config block with the source file it came from.

-AB

---

<div class="post-metadata">

### Author: ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)
#### Post date: [August 24, 2017, 8:55am UTC](https://discuss.elastic.co/t/update-of-elk-stack/98156/5 "2017-08-24T08:55:59Z")

</div>

Hi,  
You mentioned about xpack. I think it needs license. its not free right?

> [@A\_B](#):
>
> There also seems to be a new Grok debugger [Debugging Grok Expressions | Kibana User Guide [5.5] | Elastic](https://www.elastic.co/guide/en/kibana/5.5/xpack-grokdebugger.html)

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [August 24, 2017, 9:06am UTC](https://discuss.elastic.co/t/update-of-elk-stack/98156/6 "2017-08-24T09:06:58Z")

</div>

Some of the features in X-Pack does require a subscription, but there is also a free Basic license available. The features included in this are shown [on the Subscriptions page](https://www.elastic.co/subscriptions).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 21, 2017, 9:07am UTC](https://discuss.elastic.co/t/update-of-elk-stack/98156/7 "2017-09-21T09:07:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
