# Upgrade 1.3.0 -\> 5.6.4: deprecated document\_type use fileds

**URL:** <https://discuss.elastic.co/t/upgrade-1-3-0-5-6-4-deprecated-document-type-use-fileds/107202>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 10, 2017, 2:33pm UTC](https://discuss.elastic.co/t/upgrade-1-3-0-5-6-4-deprecated-document-type-use-fileds/107202 "2017-11-10T14:33:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [November 10, 2017, 2:33pm UTC](https://discuss.elastic.co/t/upgrade-1-3-0-5-6-4-deprecated-document-type-use-fileds/107202/1 "2017-11-10T14:33:27Z")

</div>

Upgraded a filebeat from 1.3.0 to 5.6.4 but it doesn't seem to collect and ship data to logstash. Upon launch filebeat complains i log about deprecated feature document\_type in my prospector:

```
2017-11-10T15:22:37+01:00 WARN DEPRECATED: document_type is deprecated. Use fields instead.
2017-11-10T15:22:37+01:00 INFO Starting prospector of type: log; id: 10372473829951082110 
2017-11-10T15:22:37+01:00 INFO Loading and starting Prospectors completed. Enabled prospectors: 1
2017-11-10T15:23:07+01:00 INFO Non-zero metrics in the last 30s: registrar.writes=1
2017-11-10T15:23:37+01:00 INFO No non-zero metrics in the last 30s

```

my prospector:

```
# cat prospectors.d/dcsstat.yml 
filebeat:
  prospectors:
    -
      paths:
        - /opt/<app server>/log/appserv.stat
      document_type: dcsstat
      fields:
        filter: owmstat

```

On service start is seems ok:

Starting filebeat: 2017/11/10 14:20:34.402507 beat.go:297: INFO Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat]  
2017/11/10 14:20:34.402542 beat.go:192: INFO Setup Beat: filebeat; Version: 5.6.4  
2017/11/10 14:20:34.402587 logstash.go:91: INFO Max Retries set to: 3  
2017/11/10 14:20:34.402623 outputs.go:108: INFO Activated logstash as output plugin.  
2017/11/10 14:20:34.402681 publish.go:300: INFO Publisher name: dcs3  
2017/11/10 14:20:34.402809 async.go:63: INFO Flush Interval set to: 1s  
2017/11/10 14:20:34.402827 async.go:64: INFO Max Bulk Size set to: 2048  
2017/11/10 14:20:34.402939 metrics.go:23: INFO Metrics logging every 30s  
2017/11/10 14:20:34.402952 config.go:114: INFO Additional config files are fetched from: /etc/filebeat/prospectors.d  
2017/11/10 14:20:34.403024 config.go:87: INFO Additional configs loaded from: /etc/filebeat/prospectors.d/dcsstat.yml  
Config OK  
[OK]

The registry stay empty:

```
# cat /var/lib/filebeat/registry 
[]

```

Is the deprecation warning hinder it to run?

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [November 13, 2017, 8:33am UTC](https://discuss.elastic.co/t/upgrade-1-3-0-5-6-4-deprecated-document-type-use-fileds/107202/2 "2017-11-13T08:33:52Z")

</div>

Even though I change docment\_type to a field so I got now complains at launch, filebeat 5.6.4 doesn't seem to ship any data to my logstash output nor update it's registry.

```
cat /etc/filebeat/prospectors.d/dcsstat.yml 
filebeat:
  prospectors:
    -
      paths:
        - /opt/<app server>/log/appserv.stat
      #document_type: dcsstat
      fields:
        type: dcsstat
        filter: owmstat

# service filebeat start
Starting filebeat: 2017/11/13 08:24:10.345106 beat.go:297: INFO Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat]
2017/11/13 08:24:10.345134 beat.go:192: INFO Setup Beat: filebeat; Version: 5.6.4
2017/11/13 08:24:10.345200 logstash.go:91: INFO Max Retries set to: 3
2017/11/13 08:24:10.345221 metrics.go:23: INFO Metrics logging every 30s
2017/11/13 08:24:10.345241 outputs.go:108: INFO Activated logstash as output plugin.
2017/11/13 08:24:10.345293 publish.go:300: INFO Publisher name: dcs3
2017/11/13 08:24:10.345474 async.go:63: INFO Flush Interval set to: 1s
2017/11/13 08:24:10.345487 async.go:64: INFO Max Bulk Size set to: 2048
2017/11/13 08:24:10.345632 config.go:114: INFO Additional config files are fetched from: /etc/filebeat/prospectors.d
2017/11/13 08:24:10.345680 config.go:87: INFO Additional configs loaded from: /etc/filebeat/prospectors.d/dcsstat.yml
Config OK
                                                           [OK]
# tail /var/log/beats/filebeat.log
2017-11-13T09:24:10+01:00 INFO Loading registrar data from /var/lib/filebeat/registry
2017-11-13T09:24:10+01:00 INFO States Loaded from registrar: 0
2017-11-13T09:24:10+01:00 INFO Loading Prospectors: 1
2017-11-13T09:24:10+01:00 INFO Starting Registrar
2017-11-13T09:24:10+01:00 INFO Start sending events to output
2017-11-13T09:24:10+01:00 INFO Prospector with previous states loaded: 0
2017-11-13T09:24:10+01:00 INFO Starting spooler: spool_size: 2048; idle_timeout: 5s
2017-11-13T09:24:10+01:00 INFO Starting prospector of type: log; id: 11876712458280652192 
2017-11-13T09:24:10+01:00 INFO Loading and starting Prospectors completed. Enabled prospectors: 1
2017-11-13T09:24:40+01:00 INFO No non-zero metrics in the last 30s
2017-11-13T09:25:10+01:00 INFO No non-zero metrics in the last 30s
2017-11-13T09:25:40+01:00 INFO No non-zero metrics in the last 30s
2017-11-13T09:26:10+01:00 INFO No non-zero metrics in the last 30s
2017-11-13T09:26:40+01:00 INFO No non-zero metrics in the last 30s
2017-11-13T09:27:10+01:00 INFO No non-zero metrics in the last 30s
2017-11-13T09:27:40+01:00 INFO No non-zero metrics in the last 30s
2017-11-13T09:28:10+01:00 INFO No non-zero metrics in the last 30s

```

File path /opt//log/appserv.stat is a symlink to latest log per day but it worked just fine with v.1.3 😕

Changing it directly to a log file instead of through a symlink makes it work. Is this a bug or feature degration?  
Using file patterns and ignore\_older,close\ __,clean\__ or enable symlinks option should fix this 🙂

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 13, 2017, 6:20pm UTC](https://discuss.elastic.co/t/upgrade-1-3-0-5-6-4-deprecated-document-type-use-fileds/107202/3 "2017-11-13T18:20:53Z")

</div>

Supporting symlinks out of the box was an oversight in filebeat versions 1.x. Using symlinks is not recommended, but if you really want to use symlinks, have a look at the `symlinks setting`([Configure inputs | Filebeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#_symlinks)).

> Is the deprecation warning hinder it to run?

The deprecation warning is no big problem, as filebeat will continue to run. But with 6.0 support for `_type` is removed/deprecated in Elasticsearch. If you still want a `type` field, you can use `fields`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2017, 6:21pm UTC](https://discuss.elastic.co/t/upgrade-1-3-0-5-6-4-deprecated-document-type-use-fileds/107202/4 "2017-12-11T18:21:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
