# WInlogbeats Error after upgrade

**URL:** <https://discuss.elastic.co/t/winlogbeats-error-after-upgrade/227791>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 13, 2020, 3:20pm UTC](https://discuss.elastic.co/t/winlogbeats-error-after-upgrade/227791 "2020-04-13T15:20:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elk\_huh](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Post date:** [April 13, 2020, 3:20pm UTC](https://discuss.elastic.co/t/winlogbeats-error-after-upgrade/227791/1 "2020-04-13T15:20:47Z")

</div>

Hi everyone i upgraded from 6.2.4 winlogbeats to 6.8

Same exact configs, same logstash conf file

I now get this error any ideas ?

[2020-04-13T11:18:30,467][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"winevents-domain-controllers-2020.04.13", :\_type=\>"doc", :routing=\>nil}, #LogStash::Event:0x6d25b8b3], :response=\>{"index"=\>{"\_index"=\>"winevents-domain-controllers-2020.04.13", "\_type"=\>"doc", "\_id"=\>"PtUedHEBacbM0UXs2o7Z", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [host] of type [keyword] in document with id 'PtUedHEBacbM0UXs2o7Z'", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:978"}}}}}

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [April 22, 2020, 2:06pm UTC](https://discuss.elastic.co/t/winlogbeats-error-after-upgrade/227791/2 "2020-04-22T14:06:14Z")

</div>

hi @Elk_huh,

It looks like your index was created with a new version of Beats that is implementing the ECS but the Logstash output isn't aware of it. ([https://www.elastic.co/guide/en/beats/winlogbeat/6.8/exported-fields-host-processor.html](https://www.elastic.co/guide/en/beats/winlogbeat/6.8/exported-fields-host-processor.html))

Can you try the following:

ECS has a `host.name` field, which corresponds to the host name being output from Logstash. By adding a Mutate filter with a `rename` directive, you can move the `host` field to `host.name` with the field-reference syntax as below to align with the schema that you already have in Elasticsearch:

```auto
filter {
  mutate {
    rename {
      "[host]" => "[host][name]"
    }
  }
}

```

Let us know if that worked in your case.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2020, 2:06pm UTC](https://discuss.elastic.co/t/winlogbeats-error-after-upgrade/227791/3 "2020-05-20T14:06:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
