http://ramsayswljlwqo7yvw3ovxhyzavllyduxkgh4rbobzkc263jyro6cjyd.onion/2018/10/13/elasticsearch-400-error-when-upgrading-fluent-winston-log-message-format.html
When you are ready to implement something more complex to support custom kibana/grafana dashboards, you’ll need to upgrade from logger . info ( ' currently have 1 active user ' ) to logger . info ({ type : ' active-users ' , count : 1 }) You’ll probably see the following in your fluentd log: 2018-10-12 02:17:57 -0400 [warn]: #0 dump an error event: error_class=Fluent::Plugin::ElasticsearchErrorHandler::ElasticsearchError error="400 - Rejected by Elasticsearch" location=nil...