# Fleet Agent: Logstash output: Invalid version of beats protocol

**URL:** <https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624>\
**Category:** Beats\
**Tags:** fleet\
**Created:** [September 17, 2022, 7:21pm UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624 "2022-09-17T19:21:25Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [September 17, 2022, 7:21pm UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/1 "2022-09-17T19:21:25Z")

</div>

This is my Logstash config

```auto
input {
  elastic_agent {
    port => 5044
    ssl => false
  }
}

filter {
    mutate {
        add_field => {
            "foo" => "bar gustavito"
        }
    }
}

output {
    elasticsearch {
        cloud_auth => "xxxx:xxx"
        cloud_id => "my_cluster:..."
        data_stream => "true"
    }
    stdout {
        codec => rubydebug {
        }
    }

```

And getting back this:

> [2022-09-17T19:18:01,567][WARN][io.netty.channel.DefaultChannelPipeline][main][8a9c9f2dc6465fb8ed9835549cd253f9a62380bfff99a3dcf3bd608f17490322] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.  
> io.netty.handler.codec.DecoderException: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 22

Fleet server is in Elastic Cloud

The agent lives in the same machine than Logstash, and the Logstash Output is set to localhost:5044 in the Fleet UI

Tried with certificates with no success (bad certificate error from Logstash) now, disabling ssl I get this error what I read is when the elasticsearch output is trying to send data to Logstash.

Any advice here?

Thank you

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [September 18, 2022, 2:37am UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/2 "2022-09-18T02:37:51Z")

</div>

@Gustavo_Llermaly - this error `io.netty.handler.codec.DecoderException: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 22` indicates that there is a mismatch in protocol in the data received by the `elastic_agent` input plugin.

Can you clarify the following:

- Which Elastic Agent version are you using?
- Which Logstash version are you using?
- Which version of the `elastic_agent` input plugin are you using?

---

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [September 18, 2022, 2:45am UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/3 "2022-09-18T02:45:23Z")

</div>

Hello @ropc

The entire stack is using 8.4.1.

This errors shows when I disable ssl . Is it possible to send data from Fleet agent to Logstash without certificates?

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [September 18, 2022, 3:08am UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/4 "2022-09-18T03:08:53Z")

</div>

Hi @Gustavo_Llermaly - let me do some research on that one. I am not aware of any explicit requirements when it comes to using Elastic Agent -\> Logstash -\> Integration Server in ESS.

---

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [September 18, 2022, 3:11am UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/5 "2022-09-18T03:11:41Z")

</div>

Thank you!.

I was able to get it working specifying a dns (localhost) when creating the cert, and providing the same cert to Logstash and Fleet UI.

Ideally I want to use the same cert in all my Elastic agents (I will have 400+ agents)

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [September 18, 2022, 4:00am UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/6 "2022-09-18T04:00:16Z")

</div>

The connection between Logstash -\> Integration Server (ESS) is encrypted - Elasticsearch Service uses standard publicly trusted certificates, so there’s no need specify other SSL settings in the Logstash pipeline.

You can refer to this documentation regarding the configuration of the Logstash pipeline: [Configure SSL/TLS for the Logstash output | Fleet and Elastic Agent Guide [8.4] | Elastic](https://www.elastic.co/guide/en/fleet/8.4/secure-logstash-connections.html#configure-ls-ssl)

---

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [September 18, 2022, 4:09am UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/7 "2022-09-18T04:09:52Z")

</div>

Could you expand on "there's no need to specify other SSL settings in the Logstash pipeline" ?

The example looks like this:

```auto
  elastic_agent {
    port => 5044
    ssl => true
    ssl_certificate_authorities => ["/path/to/ca.crt"]
    ssl_certificate => "/path/to/logstash.crt"
    ssl_key => "/path/to/logstash.pkcs8.key"
    ssl_verify_mode => "force_peer"
  }

```

So I need a certificate and key for logstash, and a certificate and key for Fleet Logstash Output?

 ![CleanShot 2022-09-18 at 01.09.26](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f0aa1a6cf39487a0338f73005cd9e875068f17e9.png)

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [September 18, 2022, 1:19pm UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/8 "2022-09-18T13:19:21Z")

</div>

> Could you expand on "there's no need to specify other SSL settings in the Logstash pipeline" ?

I was referring to the Elasticsearch output section in Logstash.

 ![Screenshot 2022-09-18 at 9.16.08 PM](https://us1.discourse-cdn.com/elastic/original/3X/8/4/84f54fbbe45f28ec14d5cbad8e0e12f519173a39.png)

> This errors shows when I disable ssl . Is it possible to send data from Fleet agent to Logstash without certificates?

If you have installed a Fleet-managed Elastic Agent, it is impossible to save the Fleet Logstash output in the Fleet UI without adding the certificates that are used to communicate between Fleet \<\> Logstash (as per [Configure SSL/TLS for the Logstash output | Fleet and Elastic Agent Guide [8.4] | Elastic](https://www.elastic.co/guide/en/fleet/8.4/secure-logstash-connections.html#add-ls-output)).

---

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [September 18, 2022, 6:24pm UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/9 "2022-09-18T18:24:16Z")

</div>

Thanks for your explanation. I'm clear the elasticsearch output doesnt need any certs.

My concern is the agent input, I need to do the simplest configuration. Which looks like it is a single cert with the logstash dns on it and shared between logstash and Fleet as disabling ssl is not possible.

Is this correct?

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [September 19, 2022, 7:26am UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/10 "2022-09-19T07:26:20Z")

</div>

That's my understanding as well - you will need to create the relevant certificates and use them in the configuration of the Logstash output for the Elastic Agent as well as the Logstash pipeline configuration.

---

<div class="post-metadata">

**Author:** ![Nima\_Rezainia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nima_rezainia/32/88626_2.png) [@Nima\_Rezainia](https://discuss.elastic.co/u/Nima_Rezainia)\
**Post date:** [September 19, 2022, 2:01pm UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/11 "2022-09-19T14:01:11Z")

</div>

Hi,

We enfroce mutual TLS between Agent and Logstash. You see this in the UI, when configuring the Logstash output.

---

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [September 19, 2022, 2:32pm UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/12 "2022-09-19T14:32:19Z")

</div>

I will summarize my weekend here, let me know If I'm making any imprecision.

1. TLS (ssl =\> true) is mandatory, if you set ssl to false you will receive bad protocol errors
2. You can create one certificate and use the same in Fleet, and in Logstash. The docs suggest to create 2: one for client (Fleet), one for server (Logstash). The Logstash one must have --ip or --dns set. The client one can omit those.
3. The logstash hostname (what you set in Fleet hosts) must match with what you configure under --dns or --ip in the certificate or you will receive "bad certificate" error \<= this is the root cause of the error, I wasnt setting --dns

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 17, 2022, 4:33pm UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624/13 "2022-10-17T16:33:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
