# Warning 'Relying on default value of \`pipeline.ecs\_compatibility' after updating to logstash 7.16.1

**URL:** <https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [December 15, 2021, 4:42pm UTC](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018 "2021-12-15T16:42:53Z")\
**Posts on this page:** 4\
**Page:** 2

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [February 14, 2022, 4:28pm UTC](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018/21 "2022-02-14T16:28:23Z")

</div>

If you want the entire pipeline to behave in 8.x EXACTLY as it does with 7.13, your best path forward is to set `pipeline.ecs_compaitibility` for the _pipeline_.

Since you are using a configuration that gives you exactly one pipeline per Logstash process, doing so in the `logstash.yml` is reasonable. If you were running multiple pipelines, then doing so for each _applicable_ pipeline in its `pipelines.yml` entry would be best.

If, for some reason, you want to avoid the easy path above (hint: you probably don't), it is possible to resolve this deprecation warning by adjusting your pipeline definition so that _each_ and _every_ plugin definition has an `ecs_compatibility => disabled` directive. This entails defining your codecs in block form, so `codec => json` becomes `codec => json { ecs_compatibility => disabled }`.

I encourage you to take the easy path, to lock in the behaviour you want for the _entire_ pipeline.

---

<div class="post-metadata">

**Author:** ![chferng](https://avatars.discourse-cdn.com/v4/letter/c/45deac/32.png) [@chferng](https://discuss.elastic.co/u/chferng)\
**Post date:** [March 2, 2022, 1:17am UTC](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018/22 "2022-03-02T01:17:40Z")

</div>

@yaauie I was already using the individual plugin definition as shown in my [earlier post here](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018/14) and that did not stop the deprecation messages from being generated.

Since I am using the helm chart and values yaml from Bitnami, I suppose I will have to turn to them to understand how the logstash.yml can be configured in the values yaml

---

<div class="post-metadata">

**Author:** ![robert\_sahakyan](https://avatars.discourse-cdn.com/v4/letter/r/f08c70/32.png) [@robert\_sahakyan](https://discuss.elastic.co/u/robert_sahakyan)\
**Post date:** [March 23, 2022, 2:52pm UTC](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018/23 "2022-03-23T14:52:31Z")

</div>

Hi @yaauie

I seem to be getting a similar issue with excessive log messages about `ecs_compatibility` & `'target' option` after upgrading to the latest version of logstash (v8.1), specifically when using the `http` plugin.

The log message I want to get rid of is:

```auto
[INFO] 2022-03-23 14:02:34.265 [[metrics]-pipeline-manager] json - ECS compatibility is enabled but 'target' option was not specified. This may cause fields to be set at the top-level of the event where they are likely to clash with the Elastic Common Schema. It is recommended to set the 'target' option to avoid potential schema conflicts (if your data is ECS compliant or non-conflicting, feel free to ignore this message)

```

I have narrowed it down to only be an issue with the `http` input plugins which seems to be causing this excessive logging across all pipelines using this plugin.

I have tried setting `ecs_compatibility: disabled` across all three levels (logstash.yml, pipelines.yml & individual plugins) but none seem to get rid of this log.

What confuses me is that when the pipeline starts, it tells me that the `ecs_compatibility` mode is set to disabled, but yet, a few lines later, it still complains about it being enabled.

That is, I first get:

```auto
... Pipeline 'metrics' is configured with 'pipeline.ecs_compatibility: disabled' setting. All plugins in this pipeline will default to 'ecs_compatibility: disabled' ...

```

followed by:

```auto
[INFO] 2022-03-23 14:02:34.265 [[metrics]-pipeline-manager] json - ECS compatibility is enabled but 'target' option was not specified. This may cause fields to be set at the top-level of the event where they are likely to clash with the Elastic Common Schema. It is recommended to set the 'target' option to avoid potential schema conflicts (if your data is ECS compliant or non-conflicting, feel free to ignore this message)

```

Here is my pipeline config:

```auto
input {

    # commented out other inputs to isolate the issue

    http { 
        port => "8111"
        type => http
    }
}

filter {
 # some code here, but it is commented out and still produces the log.
}

output { 
    pipeline {
        send_to => ["rollup_process"]
    }
}

```

pipelines.yml:

```auto
- pipeline.id metrics
  path.config: "${UAM_HOME}/pipelines/metrics.cfg"
  pipeline.workers: 1
  pipeline.ecs_compatibility: disabled

```

Please advise what I could try, or perhaps this is a bug?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2022, 2:53pm UTC](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018/24 "2022-04-20T14:53:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018.md?page=1)
