You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I have just upgraded ELK to version 6.0.0 and then parsing docker logs with logspout-logstash stopped working.
The Logstash error is this
[2017-11-30T02:11:39,765][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-2017.11.30", :_type=>"docker", :_routing=>nil}, #<LogStash::Event:0x6cf08450>], :response=>{"index"=>{"_index"=>"logstash-2017.11.30", "_type"=>"docker", "_id"=>nil, "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"Failed to parse mapping [_default_]: [include_in_all] is not allowed for indices created on or after version 6.0.0 as [_all] is deprecated. As a replacement, you can use an [copy_to] on mapping fields to create your own catch all field.", "caused_by"=>{"type"=>"mapper_parsing_exception", "reason"=>"[include_in_all] is not allowed for indices created on or after version 6.0.0 as [_all] is deprecated. As a replacement, you can use an [copy_to] on mapping fields to create your own catch all field."}}}}}
Is there a workaround?
The text was updated successfully, but these errors were encountered:
I have just upgraded ELK to version
6.0.0
and then parsing docker logs with logspout-logstash stopped working.The Logstash error is this
Is there a workaround?
The text was updated successfully, but these errors were encountered: