# Beats can not connect to Logstash

**URL:** <https://discuss.elastic.co/t/beats-can-not-connect-to-logstash/224502>\
**Category:** Logstash\
**Created:** [March 21, 2020, 4:08am UTC](https://discuss.elastic.co/t/beats-can-not-connect-to-logstash/224502 "2020-03-21T04:08:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![namesv](https://avatars.discourse-cdn.com/v4/letter/n/82dd89/32.png) [@namesv](https://discuss.elastic.co/u/namesv)\
**Post date:** [March 21, 2020, 4:08am UTC](https://discuss.elastic.co/t/beats-can-not-connect-to-logstash/224502/1 "2020-03-21T04:08:31Z")

</div>

Hi,  
I've been struggling to connect my filebeat to logstash in order to harvest the logs on node machines. Below is my error/ log from Logstash

```auto
 sudo /usr/share/logstash/bin/logstash -f ~/1phase2.conf --config.reload.automatic --path.settings /etc/logstash/
[sudo] password for vanguyen8: 
Sending Logstash logs to /var/log/logstash which is now configured via log4j2.properties
[2020-03-20T20:53:27,901][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified
[2020-03-20T20:53:28,065][INFO][logstash.runner] Starting Logstash {"logstash.version"=>"7.6.1"}
[2020-03-20T20:53:30,182][INFO][org.reflections.Reflections] Reflections took 35 ms to scan 1 urls, producing 20 keys and 40 values 
[2020-03-20T20:53:31,100][INFO][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://localhost:9200/]}}
[2020-03-20T20:53:31,331][WARN][logstash.outputs.elasticsearch][main] Restored connection to ES instance {:url=>"http://localhost:9200/"}
[2020-03-20T20:53:31,388][INFO][logstash.outputs.elasticsearch][main] ES Output version determined {:es_version=>7}
[2020-03-20T20:53:31,393][WARN][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>7}
[2020-03-20T20:53:31,457][INFO][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["http://localhost:9200"]}
[2020-03-20T20:53:31,551][INFO][logstash.outputs.elasticsearch][main] Using default mapping template
[2020-03-20T20:53:31,604][WARN][org.logstash.instrument.metrics.gauge.LazyDelegatingGauge][main] A gauge metric of an unknown type (org.jruby.specialized.RubyArrayOneObject) has been create for key: cluster_uuids. This may result in invalid serialization. It is recommended to log an issue to the responsible developer/development team.
[2020-03-20T20:53:31,612][INFO][logstash.javapipeline][main] Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>4, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50, "pipeline.max_inflight"=>500, "pipeline.sources"=>["/home/vanguyen8/1phase2.conf"], :thread=>"#<Thread:0x28cc5700 run>"}
[2020-03-20T20:53:31,629][INFO][logstash.outputs.elasticsearch][main] Attempting to install template {:manage_template=>{"index_patterns"=>"logstash-*", "version"=>60001, "settings"=>{"index.refresh_interval"=>"5s", "number_of_shards"=>1}, "mappings"=>{"dynamic_templates"=>[{"message_field"=>{"path_match"=>"message", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false}}}, {"string_fields"=>{"match"=>"*", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false, "fields"=>{"keyword"=>{"type"=>"keyword", "ignore_above"=>256}}}}}], "properties"=>{"@timestamp"=>{"type"=>"date"}, "@version"=>{"type"=>"keyword"}, "geoip"=>{"dynamic"=>true, "properties"=>{"ip"=>{"type"=>"ip"}, "location"=>{"type"=>"geo_point"}, "latitude"=>{"type"=>"half_float"}, "longitude"=>{"type"=>"half_float"}}}}}}}
[2020-03-20T20:53:32,399][INFO][logstash.inputs.beats][main] Beats inputs: Starting input listener {:address=>"0.0.0.0:5044"}
[2020-03-20T20:53:32,414][INFO][logstash.javapipeline][main] Pipeline started {"pipeline.id"=>"main"}
[2020-03-20T20:53:32,554][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[2020-03-20T20:53:32,559][INFO][org.logstash.beats.Server][main] Starting server on port: 5044
[2020-03-20T20:53:32,891][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
[2020-03-20T20:53:57,897][INFO][org.logstash.beats.BeatsHandler][main] [local: 172.20.12.11:5044, remote: 172.20.12.13:37916] Handling exception: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 71
[2020-03-20T20:53:57,905][WARN][io.netty.channel.DefaultChannelPipeline][main] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
io.netty.handler.codec.DecoderException: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 71
	at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:472) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:278) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.channel.AbstractChannelHandlerContext.access$600(AbstractChannelHandlerContext.java:38) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.channel.AbstractChannelHandlerContext$7.run(AbstractChannelHandlerContext.java:353) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.util.concurrent.DefaultEventExecutor.run(DefaultEventExecutor.java:66) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:897) [netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-all-4.1.30.Final.jar:4.1.30.Final]
	at java.lang.Thread.run(Thread.java:748) [?:1.8.0_242]
Caused by: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 71
	at org.logstash.beats.Protocol.version(Protocol.java:22) ~[logstash-input-beats-6.0.8.jar:?]
	at org.logstash.beats.BeatsParser.decode(BeatsParser.java:62) ~[logstash-input-beats-6.0.8.jar:?]
	at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:502) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:441) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	... 8 more
[2020-03-20T20:53:57,936][INFO][org.logstash.beats.BeatsHandler][main] [local: 172.20.12.11:5044, remote: 172.20.12.13:37916] Handling exception: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 69
[2020-03-20T20:53:57,938][WARN][io.netty.channel.DefaultChannelPipeline][main] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
io.netty.handler.codec.DecoderException: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 69
	at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:472) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.channelInputClosed(ByteToMessageDecoder.java:405) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.channelInputClosed(ByteToMessageDecoder.java:372) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.channelInactive(ByteToMessageDecoder.java:355) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:245) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.channel.AbstractChannelHandlerContext.access$300(AbstractChannelHandlerContext.java:38) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.channel.AbstractChannelHandlerContext$4.run(AbstractChannelHandlerContext.java:236) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.util.concurrent.DefaultEventExecutor.run(DefaultEventExecutor.java:66) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:897) [netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-all-4.1.30.Final.jar:4.1.30.Final]
	at java.lang.Thread.run(Thread.java:748) [?:1.8.0_242]
Caused by: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 69
	at org.logstash.beats.Protocol.version(Protocol.java:22) ~[logstash-input-beats-6.0.8.jar:?]
	at org.logstash.beats.BeatsParser.decode(BeatsParser.java:62) ~[logstash-input-beats-6.0.8.jar:?]
	at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:502) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:441) ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	... 10 more 

```

It seems that my logstash is denying connection from my filebeat machine due to:

```auto
[2020-03-20T20:53:57,936][INFO][org.logstash.beats.BeatsHandler][main] [local: 172.20.12.11:5044, remote: 172.20.12.13:37916] Handling exception: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 69
[2020-03-20T20:53:57,938][WARN][io.netty.channel.DefaultChannelPipeline][main] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
io.netty.handler.codec.DecoderException: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 69 

```

or

```auto
[2020-03-20T20:55:24,685][INFO][org.logstash.beats.BeatsHandler][main] [local: 172.20.12.11:5044, remote: 172.20.12.13:37920] Handling exception: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 71
[2020-03-20T20:55:24,691][WARN][io.netty.channel.DefaultChannelPipeline][main] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
io.netty.handler.codec.DecoderException: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 71

```

I can ping my ELK machine where the Logstash is located and the logstash port which is 5044, but no connection from beats to logstash.

Every help is appreciated  
Thanks.

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [March 23, 2020, 4:25am UTC](https://discuss.elastic.co/t/beats-can-not-connect-to-logstash/224502/2 "2020-03-23T04:25:31Z")

</div>

Hi @namesv, welcome to our community forums!

This [Discuss post](https://discuss.elastic.co/t/fail-to-ship-data-from-metribeat-to-logstash/208876) seems to be related. You should check your TLS/SSL configuration (in both Filebeat / Logstash).

---

<div class="post-metadata">

**Author:** ![namesv](https://avatars.discourse-cdn.com/v4/letter/n/82dd89/32.png) [@namesv](https://discuss.elastic.co/u/namesv)\
**Post date:** [March 23, 2020, 5:04am UTC](https://discuss.elastic.co/t/beats-can-not-connect-to-logstash/224502/3 "2020-03-23T05:04:32Z")

</div>

The problem of mine was that I was trying to ship data to logstash and I did not uncomment line `output.logstash`, and left `output.elasticsearch` uncommented.  
I uncommented `output.logstash` line and comment `output.elasticsearch` so that data is shipped to logstash and things work fine

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [March 23, 2020, 5:53am UTC](https://discuss.elastic.co/t/beats-can-not-connect-to-logstash/224502/4 "2020-03-23T05:53:28Z")

</div>

@namesv Thanks for sharing your feedback 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2020, 6:04am UTC](https://discuss.elastic.co/t/beats-can-not-connect-to-logstash/224502/5 "2020-04-20T06:04:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
