Zero-day-exploit in log4j2 which is part of elasticsearch

Yes. It does need to be restarted. Additionally, you might need to change the ownership of jar to logtash:logstash or whatever it was before, in case it got changed while updating the jar by removing the class.

1 Like