# Exception caught on transport layer (0.20.1)

**URL:** <https://discuss.elastic.co/t/exception-caught-on-transport-layer-0-20-1/10107>\
**Category:** Elasticsearch\
**Created:** [December 18, 2012, 5:02pm UTC](https://discuss.elastic.co/t/exception-caught-on-transport-layer-0-20-1/10107 "2012-12-18T17:02:28Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ognen\_Duzlevski](https://avatars.discourse-cdn.com/v4/letter/o/cab0a1/32.png) [@Ognen\_Duzlevski](https://discuss.elastic.co/u/Ognen_Duzlevski)\
**Post date:** [December 18, 2012, 5:02pm UTC](https://discuss.elastic.co/t/exception-caught-on-transport-layer-0-20-1/10107/1 "2012-12-18T17:02:28Z")

</div>

I run elasticsearch on a debian server. It starts up, the log is fine until  
I run logstash. Then I start getting errors in the elasticsearch logs as  
below. Any idea what is going on?

Thanks!  
Ognen

[2012-12-18 10:51:42,111][INFO][node] [command  
center] {0.20.1}[8901]: initializing ...  
[2012-12-18 10:51:42,122][INFO][plugins] [command  
center] loaded [], sites []  
[2012-12-18 10:51:46,686][INFO][node] [command  
center] {0.20.1}[8901]: initialized  
[2012-12-18 10:51:46,686][INFO][node] [command  
center] {0.20.1}[8901]: starting ...  
[2012-12-18 10:51:46,879][INFO][transport] [command  
center] bound\_address {inet[/0:0:0:0:0:0:0:0:9300]}, publish\_address  
{inet[/10.6.0.88:9300]}  
[2012-12-18 10:51:49,933][INFO][cluster.service] [command  
center] new\_master [command  
center][erqnAKNCQUu\_tUyLUSgS6w][inet[/10.6.0.88:9300]]{master=true},  
reason: zen-disco-join (elected\_as\_master)  
[2012-12-18 10:51:49,992][INFO][discovery] [command  
center] [server]/erqnAKNCQUu\_tUyLUSgS6w  
[2012-12-18 10:51:50,042][INFO][http] [command  
center] bound\_address {inet[/0:0:0:0:0:0:0:0:9200]}, publish\_address  
{inet[/10.6.0.88:9200]}  
[2012-12-18 10:51:50,043][INFO][node] [command  
center] {0.20.1}[8901]: started  
[2012-12-18 10:51:50,230][INFO][gateway] [command  
center] recovered [0] indices into cluster\_state  
[2012-12-18 10:54:31,674][WARN][transport.netty] [command  
center] exception caught on transport layer [[id: 0x4d0e98fc,  
/10.6.0.88:58532 =\> /10.6.0.88:9300]], closing connection  
java.io.StreamCorruptedException: invalid internal transport message format  
at  
org.elasticsearch.transport.netty.SizeHeaderFrameDecoder.decode(SizeHeaderFrameDecoder.java:27)  
at  
org.elasticsearch.common.netty.handler.codec.frame.FrameDecoder.callDecode(FrameDecoder.java:422)  
at  
org.elasticsearch.common.netty.handler.codec.frame.FrameDecoder.messageReceived(FrameDecoder.java:303)  
at  
org.elasticsearch.common.netty.channel.SimpleChannelUpstreamHandler.handleUpstream(SimpleChannelUpstreamHandler.java:70)  
at  
org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:558)  
at  
org.elasticsearch.common.netty.channel.DefaultChannelPipeline$DefaultChannelHandlerContext.sendUpstream(DefaultChannelPipeline.java:786)  
at  
org.elasticsearch.common.netty.OpenChannelsHandler.handleUpstream(OpenChannelsHandler.java:74)  
at  
org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:558)  
at  
org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:553)  
at  
org.elasticsearch.common.netty.channel.Channels.fireMessageReceived(Channels.java:268)  
at  
org.elasticsearch.common.netty.channel.Channels.fireMessageReceived(Channels.java:255)  
at  
org.elasticsearch.common.netty.channel.socket.nio.NioWorker.read(NioWorker.java:84)  
at  
org.elasticsearch.common.netty.channel.socket.nio.AbstractNioWorker.processSelectedKeys(AbstractNioWorker.java:471)  
at  
org.elasticsearch.common.netty.channel.socket.nio.AbstractNioWorker.run(AbstractNioWorker.java:332)  
at  
org.elasticsearch.common.netty.channel.socket.nio.NioWorker.run(NioWorker.java:35)  
at  
org.elasticsearch.common.netty.util.ThreadRenamingRunnable.run(ThreadRenamingRunnable.java:102)  
enthought-es.log

--

---

<div class="post-metadata">

**Author:** ![mvg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvg/32/98890_2.png) [@mvg](https://discuss.elastic.co/u/mvg)\
**Post date:** [December 18, 2012, 8:05pm UTC](https://discuss.elastic.co/t/exception-caught-on-transport-layer-0-20-1/10107/2 "2012-12-18T20:05:24Z")

</div>

Are all other nodes also running version 0.20.1?

On 18 December 2012 18:02, Ognen Duzlevski [ognen@enthought.com](mailto:ognen@enthought.com) wrote:

> I run elasticsearch on a debian server. It starts up, the log is fine until  
> I run logstash. Then I start getting errors in the elasticsearch logs as  
> below. Any idea what is going on?
> 
> Thanks!  
> Ognen
> 
> [2012-12-18 10:51:42,111][INFO][node] [command center]  
> {0.20.1}[8901]: initializing ...  
> [2012-12-18 10:51:42,122][INFO][plugins] [command center]  
> loaded , sites   
> [2012-12-18 10:51:46,686][INFO][node] [command center]  
> {0.20.1}[8901]: initialized  
> [2012-12-18 10:51:46,686][INFO][node] [command center]  
> {0.20.1}[8901]: starting ...  
> [2012-12-18 10:51:46,879][INFO][transport] [command center]  
> bound\_address {inet[/0:0:0:0:0:0:0:0:9300]}, publish\_address  
> {inet[/10.6.0.88:9300]}  
> [2012-12-18 10:51:49,933][INFO][cluster.service] [command center]  
> new\_master [command  
> center][erqnAKNCQUu\_tUyLUSgS6w][inet[/10.6.0.88:9300]]{master=true}, reason:  
> zen-disco-join (elected\_as\_master)  
> [2012-12-18 10:51:49,992][INFO][discovery] [command center]  
> [server]/erqnAKNCQUu\_tUyLUSgS6w  
> [2012-12-18 10:51:50,042][INFO][http] [command center]  
> bound\_address {inet[/0:0:0:0:0:0:0:0:9200]}, publish\_address  
> {inet[/10.6.0.88:9200]}  
> [2012-12-18 10:51:50,043][INFO][node] [command center]  
> {0.20.1}[8901]: started  
> [2012-12-18 10:51:50,230][INFO][gateway] [command center]  
> recovered [0] indices into cluster\_state  
> [2012-12-18 10:54:31,674][WARN][transport.netty] [command center]  
> exception caught on transport layer [[id: 0x4d0e98fc, /10.6.0.88:58532 =\>  
> /10.6.0.88:9300]], closing connection  
> java.io.StreamCorruptedException: invalid internal transport message format  
> at  
> org.elasticsearch.transport.netty.SizeHeaderFrameDecoder.decode(SizeHeaderFrameDecoder.java:27)  
> at  
> org.elasticsearch.common.netty.handler.codec.frame.FrameDecoder.callDecode(FrameDecoder.java:422)  
> at  
> org.elasticsearch.common.netty.handler.codec.frame.FrameDecoder.messageReceived(FrameDecoder.java:303)  
> at  
> org.elasticsearch.common.netty.channel.SimpleChannelUpstreamHandler.handleUpstream(SimpleChannelUpstreamHandler.java:70)  
> at  
> org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:558)  
> at  
> org.elasticsearch.common.netty.channel.DefaultChannelPipeline$DefaultChannelHandlerContext.sendUpstream(DefaultChannelPipeline.java:786)  
> at  
> org.elasticsearch.common.netty.OpenChannelsHandler.handleUpstream(OpenChannelsHandler.java:74)  
> at  
> org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:558)  
> at  
> org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:553)  
> at  
> org.elasticsearch.common.netty.channel.Channels.fireMessageReceived(Channels.java:268)  
> at  
> org.elasticsearch.common.netty.channel.Channels.fireMessageReceived(Channels.java:255)  
> at  
> org.elasticsearch.common.netty.channel.socket.nio.NioWorker.read(NioWorker.java:84)  
> at  
> org.elasticsearch.common.netty.channel.socket.nio.AbstractNioWorker.processSelectedKeys(AbstractNioWorker.java:471)  
> at  
> org.elasticsearch.common.netty.channel.socket.nio.AbstractNioWorker.run(AbstractNioWorker.java:332)  
> at  
> org.elasticsearch.common.netty.channel.socket.nio.NioWorker.run(NioWorker.java:35)  
> at  
> org.elasticsearch.common.netty.util.ThreadRenamingRunnable.run(ThreadRenamingRunnable.java:102)  
> enthought-es.log
> 
> --

--  
Met vriendelijke groet,

Martijn van Groningen

--

---

<div class="post-metadata">

**Author:** ![Ognen\_Duzlevski](https://avatars.discourse-cdn.com/v4/letter/o/cab0a1/32.png) [@Ognen\_Duzlevski](https://discuss.elastic.co/u/Ognen_Duzlevski)\
**Post date:** [December 19, 2012, 4:21am UTC](https://discuss.elastic.co/t/exception-caught-on-transport-layer-0-20-1/10107/3 "2012-12-19T04:21:01Z")

</div>

On Tuesday, December 18, 2012 2:05:24 PM UTC-6, Martijn v Groningen wrote:

> Are all other nodes also running version 0.20.1?

No other nodes.  
OD

> On 18 December 2012 18:02, Ognen Duzlevski \<[og...@enthought.com](mailto:og...@enthought.com)\<javascript:\>\>  
> wrote:
> 
> > I run elasticsearch on a debian server. It starts up, the log is fine  
> > until  
> > I run logstash. Then I start getting errors in the elasticsearch logs as  
> > below. Any idea what is going on?
> > 
> > Thanks!  
> > Ognen
> > 
> > [2012-12-18 10:51:42,111][INFO][node] [command  
> > center]  
> > {0.20.1}[8901]: initializing ...  
> > [2012-12-18 10:51:42,122][INFO][plugins] [command  
> > center]  
> > loaded , sites   
> > [2012-12-18 10:51:46,686][INFO][node] [command  
> > center]  
> > {0.20.1}[8901]: initialized  
> > [2012-12-18 10:51:46,686][INFO][node] [command  
> > center]  
> > {0.20.1}[8901]: starting ...  
> > [2012-12-18 10:51:46,879][INFO][transport] [command  
> > center]  
> > bound\_address {inet[/0:0:0:0:0:0:0:0:9300]}, publish\_address  
> > {inet[/10.6.0.88:9300]}  
> > [2012-12-18 10:51:49,933][INFO][cluster.service] [command  
> > center]  
> > new\_master [command  
> > center][erqnAKNCQUu\_tUyLUSgS6w][inet[/10.6.0.88:9300]]{master=true},  
> > reason:  
> > zen-disco-join (elected\_as\_master)  
> > [2012-12-18 10:51:49,992][INFO][discovery] [command  
> > center]  
> > [server]/erqnAKNCQUu\_tUyLUSgS6w  
> > [2012-12-18 10:51:50,042][INFO][http] [command  
> > center]  
> > bound\_address {inet[/0:0:0:0:0:0:0:0:9200]}, publish\_address  
> > {inet[/10.6.0.88:9200]}  
> > [2012-12-18 10:51:50,043][INFO][node] [command  
> > center]  
> > {0.20.1}[8901]: started  
> > [2012-12-18 10:51:50,230][INFO][gateway] [command  
> > center]  
> > recovered [0] indices into cluster\_state  
> > [2012-12-18 10:54:31,674][WARN][transport.netty] [command  
> > center]  
> > exception caught on transport layer [[id: 0x4d0e98fc, /10.6.0.88:58532=\>  
> > /10.6.0.88:9300]], closing connection  
> > java.io.StreamCorruptedException: invalid internal transport message  
> > format  
> > at
> 
> org.elasticsearch.transport.netty.SizeHeaderFrameDecoder.decode(SizeHeaderFrameDecoder.java:27)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.handler.codec.frame.FrameDecoder.callDecode(FrameDecoder.java:422)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.handler.codec.frame.FrameDecoder.messageReceived(FrameDecoder.java:303)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.SimpleChannelUpstreamHandler.handleUpstream(SimpleChannelUpstreamHandler.java:70)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:558)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.DefaultChannelPipeline$DefaultChannelHandlerContext.sendUpstream(DefaultChannelPipeline.java:786)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.OpenChannelsHandler.handleUpstream(OpenChannelsHandler.java:74)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:558)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:553)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.Channels.fireMessageReceived(Channels.java:268)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.Channels.fireMessageReceived(Channels.java:255)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.socket.nio.NioWorker.read(NioWorker.java:84)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.socket.nio.AbstractNioWorker.processSelectedKeys(AbstractNioWorker.java:471)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.socket.nio.AbstractNioWorker.run(AbstractNioWorker.java:332)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.channel.socket.nio.NioWorker.run(NioWorker.java:35)
> 
> > ```
> > at 
> > 
> > ```
> 
> org.elasticsearch.common.netty.util.ThreadRenamingRunnable.run(ThreadRenamingRunnable.java:102)
> 
> > enthought-es.log
> > 
> > --
> 
> --  
> Met vriendelijke groet,
> 
> Martijn van Groningen

--

---

<div class="post-metadata">

**Author:** ![Ognen\_Duzlevski](https://avatars.discourse-cdn.com/v4/letter/o/cab0a1/32.png) [@Ognen\_Duzlevski](https://discuss.elastic.co/u/Ognen_Duzlevski)\
**Post date:** [December 19, 2012, 4:23am UTC](https://discuss.elastic.co/t/exception-caught-on-transport-layer-0-20-1/10107/4 "2012-12-19T04:23:34Z")

</div>

Sorry, I meant to say, I am not running any other nodes, this is just an  
experimental setup to see if I can ship syslogs from various machines to  
logsash and use a standalone elasticsearch.  
Ognen

On Tuesday, December 18, 2012 10:21:01 PM UTC-6, Ognen Duzlevski wrote:

> On Tuesday, December 18, 2012 2:05:24 PM UTC-6, Martijn v Groningen wrote:
> 
> > Are all other nodes also running version 0.20.1?
> 
> No other nodes.  
> OD
> 
> > On 18 December 2012 18:02, Ognen Duzlevski [og...@enthought.com](mailto:og...@enthought.com) wrote:
> > 
> > > I run elasticsearch on a debian server. It starts up, the log is fine  
> > > until  
> > > I run logstash. Then I start getting errors in the elasticsearch logs  
> > > as  
> > > below. Any idea what is going on?
> > > 
> > > Thanks!  
> > > Ognen
> > > 
> > > [2012-12-18 10:51:42,111][INFO][node] [command  
> > > center]  
> > > {0.20.1}[8901]: initializing ...  
> > > [2012-12-18 10:51:42,122][INFO][plugins] [command  
> > > center]  
> > > loaded , sites   
> > > [2012-12-18 10:51:46,686][INFO][node] [command  
> > > center]  
> > > {0.20.1}[8901]: initialized  
> > > [2012-12-18 10:51:46,686][INFO][node] [command  
> > > center]  
> > > {0.20.1}[8901]: starting ...  
> > > [2012-12-18 10:51:46,879][INFO][transport] [command  
> > > center]  
> > > bound\_address {inet[/0:0:0:0:0:0:0:0:9300]}, publish\_address  
> > > {inet[/10.6.0.88:9300]}  
> > > [2012-12-18 10:51:49,933][INFO][cluster.service] [command  
> > > center]  
> > > new\_master [command  
> > > center][erqnAKNCQUu\_tUyLUSgS6w][inet[/10.6.0.88:9300]]{master=true},  
> > > reason:  
> > > zen-disco-join (elected\_as\_master)  
> > > [2012-12-18 10:51:49,992][INFO][discovery] [command  
> > > center]  
> > > [server]/erqnAKNCQUu\_tUyLUSgS6w  
> > > [2012-12-18 10:51:50,042][INFO][http] [command  
> > > center]  
> > > bound\_address {inet[/0:0:0:0:0:0:0:0:9200]}, publish\_address  
> > > {inet[/10.6.0.88:9200]}  
> > > [2012-12-18 10:51:50,043][INFO][node] [command  
> > > center]  
> > > {0.20.1}[8901]: started  
> > > [2012-12-18 10:51:50,230][INFO][gateway] [command  
> > > center]  
> > > recovered [0] indices into cluster\_state  
> > > [2012-12-18 10:54:31,674][WARN][transport.netty] [command  
> > > center]  
> > > exception caught on transport layer [[id: 0x4d0e98fc, /10.6.0.88:58532=\>  
> > > /10.6.0.88:9300]], closing connection  
> > > java.io.StreamCorruptedException: invalid internal transport message  
> > > format  
> > > at
> > 
> > org.elasticsearch.transport.netty.SizeHeaderFrameDecoder.decode(SizeHeaderFrameDecoder.java:27)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.handler.codec.frame.FrameDecoder.callDecode(FrameDecoder.java:422)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.handler.codec.frame.FrameDecoder.messageReceived(FrameDecoder.java:303)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.SimpleChannelUpstreamHandler.handleUpstream(SimpleChannelUpstreamHandler.java:70)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:558)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.DefaultChannelPipeline$DefaultChannelHandlerContext.sendUpstream(DefaultChannelPipeline.java:786)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.OpenChannelsHandler.handleUpstream(OpenChannelsHandler.java:74)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:558)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:553)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.Channels.fireMessageReceived(Channels.java:268)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.Channels.fireMessageReceived(Channels.java:255)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.socket.nio.NioWorker.read(NioWorker.java:84)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.socket.nio.AbstractNioWorker.processSelectedKeys(AbstractNioWorker.java:471)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.socket.nio.AbstractNioWorker.run(AbstractNioWorker.java:332)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.channel.socket.nio.NioWorker.run(NioWorker.java:35)
> > 
> > > ```
> > > at 
> > > 
> > > ```
> > 
> > org.elasticsearch.common.netty.util.ThreadRenamingRunnable.run(ThreadRenamingRunnable.java:102)
> > 
> > > enthought-es.log
> > > 
> > > --
> > 
> > --  
> > Met vriendelijke groet,
> > 
> > Martijn van Groningen

--

---

<div class="post-metadata">

**Author:** ![radu\_gheorghe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/radu_gheorghe/32/556_2.png) [@radu\_gheorghe](https://discuss.elastic.co/u/radu_gheorghe)\
**Post date:** [December 19, 2012, 8:39am UTC](https://discuss.elastic.co/t/exception-caught-on-transport-layer-0-20-1/10107/5 "2012-12-19T08:39:57Z")

</div>

Hi Ognen,

I would assume the ES client bound to your logstash is using a different  
version. For example the latest (1.1.5) uses ES 0.19.8:

> **[Elasticsearch output plugin | Logstash Plugins](https://www.elastic.co/docs/reference/logstash/plugins/plugins-outputs-elasticsearch)**
>
> Plugin version: v12.1.0 (Other versions), Released on: 2025-10-07, Changelog. For questions about the plugin, open a topic in the Discuss forums. For...

So you can either use ES 0.19.8 for logstash 1.1.15, or you can try  
elasticsearch\_http:

> **[Elasticsearch output plugin | Logstash Plugins](https://www.elastic.co/docs/reference/logstash/plugins/plugins-outputs-elasticsearch)**
>
> Plugin version: v12.1.0 (Other versions), Released on: 2025-10-07, Changelog. For questions about the plugin, open a topic in the Discuss forums. For...

Martijn asked about your other nodes because logstash's elasticsearch  
output uses ES Node Client:

> **[Elastic — The Search AI Company](https://www.elastic.co)**
>
> Power insights and outcomes with The Elastic Search AI Platform. See into your data and find answers that matter with enterprise solutions designed to help you accelerate time to insight. Try Elastic ...

Which is basically another node 🙂 And your nodes should run the same  
version of ES.

## Best regards, Radu

[http://sematext.com/](http://sematext.com/) -- Elasticsearch -- Solr -- Lucene

On Wed, Dec 19, 2012 at 6:23 AM, Ognen Duzlevski [ognen@enthought.com](mailto:ognen@enthought.com)wrote:

> Sorry, I meant to say, I am not running any other nodes, this is just an  
> experimental setup to see if I can ship syslogs from various machines to  
> logsash and use a standalone elasticsearch.  
> Ognen
> 
> On Tuesday, December 18, 2012 10:21:01 PM UTC-6, Ognen Duzlevski wrote:
> 
> > On Tuesday, December 18, 2012 2:05:24 PM UTC-6, Martijn v Groningen wrote:
> > 
> > > Are all other nodes also running version 0.20.1?
> > 
> > No other nodes.  
> > OD
> > 
> > > On 18 December 2012 18:02, Ognen Duzlevski [og...@enthought.com](mailto:og...@enthought.com) wrote:
> > > 
> > > > I run elasticsearch on a debian server. It starts up, the log is fine  
> > > > until  
> > > > I run logstash. Then I start getting errors in the elasticsearch logs  
> > > > as  
> > > > below. Any idea what is going on?
> > > > 
> > > > Thanks!  
> > > > Ognen
> > > > 
> > > > [2012-12-18 10:51:42,111][INFO][node] [command  
> > > > center]  
> > > > {0.20.1}[8901]: initializing ...  
> > > > [2012-12-18 10:51:42,122][INFO][plugins] [command  
> > > > center]  
> > > > loaded , sites   
> > > > [2012-12-18 10:51:46,686][INFO][node] [command  
> > > > center]  
> > > > {0.20.1}[8901]: initialized  
> > > > [2012-12-18 10:51:46,686][INFO][node] [command  
> > > > center]  
> > > > {0.20.1}[8901]: starting ...  
> > > > [2012-12-18 10:51:46,879][INFO][transport] [command  
> > > > center]  
> > > > bound\_address {inet[/0:0:0:0:0:0:0:0:9300]}, publish\_address  
> > > > {inet[/10.6.0.88:9300]}  
> > > > [2012-12-18 10:51:49,933][INFO][cluster.service] [command  
> > > > center]  
> > > > new\_master [command  
> > > > center][erqnAKNCQUu\_\*\*tUyLUSgS6w][inet[/10.6.0.88:\*\*9300]]{master=true},  
> > > > reason:  
> > > > zen-disco-join (elected\_as\_master)  
> > > > [2012-12-18 10:51:49,992][INFO][discovery] [command  
> > > > center]  
> > > > [server]/erqnAKNCQUu\_\*\*tUyLUSgS6w  
> > > > [2012-12-18 10:51:50,042][INFO][http] [command  
> > > > center]  
> > > > bound\_address {inet[/0:0:0:0:0:0:0:0:9200]}, publish\_address  
> > > > {inet[/10.6.0.88:9200]}  
> > > > [2012-12-18 10:51:50,043][INFO][node] [command  
> > > > center]  
> > > > {0.20.1}[8901]: started  
> > > > [2012-12-18 10:51:50,230][INFO][gateway] [command  
> > > > center]  
> > > > recovered [0] indices into cluster\_state  
> > > > [2012-12-18 10:54:31,674][WARN][transport.netty] [command  
> > > > center]  
> > > > exception caught on transport layer [[id: 0x4d0e98fc, /10.6.0.88:58532=\>  
> > > > /10.6.0.88:9300]], closing connection  
> > > > [java.io](http://java.io).\*\*StreamCorruptedException: invalid internal transport  
> > > > message format  
> > > > at  
> > > > org.elasticsearch.transport. **netty.SizeHeaderFrameDecoder.**  
> > > > decode(SizeHeaderFrameDecoder.\*\*java:27)  
> > > > at  
> > > > org.elasticsearch.common. **netty.handler.codec.frame.**  
> > > > FrameDecoder.callDecode(\*\*FrameDecoder.java:422)  
> > > > at  
> > > > org.elasticsearch.common. **netty.handler.codec.frame.**  
> > > > FrameDecoder.messageReceived(\*\*FrameDecoder.java:303)  
> > > > at  
> > > > org.elasticsearch.common. **netty.channel.**  
> > > > SimpleChannelUpstreamHandler.**handleUpstream(**  
> > > > SimpleChannelUpstreamHandler.\*\*java:70)  
> > > > at  
> > > > org.elasticsearch.common.\*\*netty.channel. **DefaultChannelPipeline.**  
> > > > sendUpstream(\*\*DefaultChannelPipeline.java:\*\*558)  
> > > > at  
> > > > org.elasticsearch.common.\*\*netty.channel. **DefaultChannelPipeline$**  
> > > > DefaultChannelHandlerContext.**sendUpstream(**  
> > > > DefaultChannelPipeline.java:\*\*786)  
> > > > at  
> > > > org.elasticsearch.common.\*\*netty.OpenChannelsHandler.\*\*handleUpstream(  
> > > > \*\*OpenChannelsHandler.java:74)  
> > > > at  
> > > > org.elasticsearch.common.\*\*netty.channel. **DefaultChannelPipeline.**  
> > > > sendUpstream(\*\*DefaultChannelPipeline.java:\*\*558)  
> > > > at  
> > > > org.elasticsearch.common.\*\*netty.channel. **DefaultChannelPipeline.**  
> > > > sendUpstream(\*\*DefaultChannelPipeline.java:\*\*553)  
> > > > at  
> > > > org.elasticsearch.common. **netty.channel.Channels.**  
> > > > fireMessageReceived(Channels.\*\*java:268)  
> > > > at  
> > > > org.elasticsearch.common. **netty.channel.Channels.**  
> > > > fireMessageReceived(Channels.\*\*java:255)  
> > > > at  
> > > > org.elasticsearch.common. **netty.channel.socket.nio.**  
> > > > NioWorker.read(NioWorker.java:\*\*84)  
> > > > at  
> > > > org.elasticsearch.common. **netty.channel.socket.nio.**  
> > > > AbstractNioWorker.\*\*processSelectedKeys(\*\*AbstractNioWorker.java:471)  
> > > > at  
> > > > org.elasticsearch.common. **netty.channel.socket.nio.**  
> > > > AbstractNioWorker.run(\*\*AbstractNioWorker.java:332)  
> > > > at  
> > > > org.elasticsearch.common. **netty.channel.socket.nio.**  
> > > > NioWorker.run(NioWorker.java:\*\*35)  
> > > > at  
> > > > org.elasticsearch.common.\*\*netty.util.**ThreadRenamingRunnable.run(**  
> > > > ThreadRenamingRunnable.java:\*\*102)  
> > > > enthought-es.log
> > > > 
> > > > --
> > > 
> > > --  
> > > Met vriendelijke groet,
> > > 
> > > Martijn van Groningen
> > 
> > --

--

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [December 20, 2012, 1:20am UTC](https://discuss.elastic.co/t/exception-caught-on-transport-layer-0-20-1/10107/6 "2012-12-20T01:20:57Z")

</div>

Can you check if your logstash client setup uses port 9200, or 9300? 9200  
is the HTTP REST API port for logstash afaik.

Jörg

--

---

<div class="post-metadata">

**Author:** ![Ognen\_Duzlevski](https://avatars.discourse-cdn.com/v4/letter/o/cab0a1/32.png) [@Ognen\_Duzlevski](https://discuss.elastic.co/u/Ognen_Duzlevski)\
**Post date:** [December 26, 2012, 9:06pm UTC](https://discuss.elastic.co/t/exception-caught-on-transport-layer-0-20-1/10107/7 "2012-12-26T21:06:11Z")

</div>

Radu,

On Wednesday, December 19, 2012 2:39:57 AM UTC-6, Radu Gheorghe wrote:

> Hi Ognen,
> 
> I would assume the ES client bound to your logstash is using a different  
> version. For example the latest (1.1.5) uses ES 0.19.8:  
> [Elasticsearch output plugin | Logstash Reference [8.11] | Elastic](http://logstash.net/docs/1.1.5/outputs/elasticsearch)
> 
> So you can either use ES 0.19.8 for logstash 1.1.15, or you can try  
> elasticsearch\_http:  
> [Elasticsearch output plugin | Logstash Reference [8.11] | Elastic](http://logstash.net/docs/1.1.5/outputs/elasticsearch_http)
> 
> Martijn asked about your other nodes because logstash's elasticsearch  
> output uses ES Node Client:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/java-api/client.html)
> 
> Which is basically another node 🙂 And your nodes should run the same  
> version of ES.

Thank you, that was it - I installed the 0.19.8 elasticsearch and ran  
logstash 1.1.5 and it all works now 🙂  
OD

--

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:58am UTC](https://discuss.elastic.co/t/exception-caught-on-transport-layer-0-20-1/10107/8 "2017-07-06T02:58:27Z")

</div>


