# Invalid protocol when filebeat send to logstash

**URL:** <https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 15, 2022, 11:06am UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681 "2022-10-15T11:06:06Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 11:06am UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/1 "2022-10-15T11:06:06Z")

</div>

```auto
[2022-10-15T11:01:12,651][INFO][org.logstash.beats.BeatsHandler][terza][7bd5f0adbbfa46b9e9ef1e064135c6f8c54b821b69f260da353a735193b5fe7d] [local: 172.19.1.12:5044, remote: 172.19.0.1:53380] Handling exception: io.netty.handler.codec.DecoderException: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 71 (caused by: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 71)
[2022-10-15T11:01:12,655][WARN][io.netty.channel.DefaultChannelPipeline][terza][7bd5f0adbbfa46b9e9ef1e064135c6f8c54b821b69f260da353a735193b5fe7d] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.

```

hello i use filebeat 7 and logstash 8 is possible?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 15, 2022, 11:19am UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/2 "2022-10-15T11:19:50Z")

</div>

According to the [support matrix](https://www.elastic.co/support/matrix#matrix_compatibility) it seems Beats 7.17 is the earliest version compatible with Logstash 8.

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 11:27am UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/3 "2022-10-15T11:27:37Z")

</div>

hell this is my conf on logstash

```auto
input {
      beats { # Notice the input is now being taken from 'Beats' instead of a 'file'
        type => "logs"
        port => "5044" 
      }
}

output {

		elasticsearch {
			hosts => ["elasticsearch:9200"]
			index => "prova"
		}
		

		stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 15, 2022, 11:30am UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/4 "2022-10-15T11:30:33Z")

</div>

Which version of Filebeat are you using?

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 12:03pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/5 "2022-10-15T12:03:42Z")

</div>

now i use 8.4.3

i change config but

```auto
[2022-10-15T11:53:19,093][ERROR][logstash.inputs.tcp][terza][29b59b8e3f0e92a4cd1027566c11d7d30488054b6d1fb1a8ce632fd78656b0a1] localhost/127.0.0.1:60412: closing due:
org.jruby.exceptions.RuntimeError: (RuntimeError) Not implemented

```

```auto

input {
    tcp {
        port => 5044
        type => logs
        codec => rubydebug
    }
}

output {

		elasticsearch {
			hosts => ["localhost:9200"]
			index => "prova2"
		}
		

		stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 15, 2022, 12:14pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/6 "2022-10-15T12:14:07Z")

</div>

> [@Nikolas1306](#):
>
> ```auto
> type => logs
> codec => rubydebug
> 
> ```

Try removing this. A rubydebug codec does not make sense for an input.

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 12:17pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/7 "2022-10-15T12:17:11Z")

</div>

if use in logstash conf

```auto
input {
    beats {
      host => "localhost"
      port => 5044
    }
}

output {

		elasticsearch {
			hosts => ["localhost:9200"]
			index => "prova2"
		}
		

		stdout { codec => rubydebug }
}

```

```auto
[2022-10-15T12:16:04,651][INFO][org.logstash.beats.BeatsHandler][terza][0bc359621600c3614b91a3cd92e6ee0d262ea0ed4fe2b06cfcd2d59f46baf37f] [local: 127.0.0.1:5044, remote: 127.0.0.1:45118] Handling exception: io.netty.handler.codec.DecoderException: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 69 (caused by: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 69)
[2022-10-15T12:16:04,651][WARN][io.netty.channel.DefaultChannelPipeline][terza][0bc359621600c3614b91a3cd92e6ee0d262ea0ed4fe2b06cfcd2d59f46baf37f] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
io.netty.handler.codec.DecoderException: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 69
	at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:477) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.channelInputClosed(ByteToMessageDecoder.java:404) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.channelInputClosed(ByteToMessageDecoder.java:371) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.channelInactive(ByteToMessageDecoder.java:354) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:262) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.channel.AbstractChannelHandlerContext.access$300(AbstractChannelHandlerContext.java:61) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.channel.AbstractChannelHandlerContext$4.run(AbstractChannelHandlerContext.java:253) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.util.concurrent.DefaultEventExecutor.run(DefaultEventExecutor.java:66) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.util.concurrent.SingleThreadEventExecutor$4.run(SingleThreadEventExecutor.java:989) [netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.util.internal.ThreadExecutorMap$2.run(ThreadExecutorMap.java:74) [netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-all-4.1.65.Final.jar:4.1.65.Final]
	at java.lang.Thread.run(Thread.java:833) [?:?]
Caused by: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 69
	at org.logstash.beats.Protocol.version(Protocol.java:22) ~[logstash-input-beats-6.4.1.jar:?]
	at org.logstash.beats.BeatsParser.decode(BeatsParser.java:62) ~[logstash-input-beats-6.4.1.jar:?]
	at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:507) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:446) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
	... 11 more

```

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 12:18pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/8 "2022-10-15T12:18:51Z")

</div>

filebeat conf

```auto
filebeat.inputs:
  - type: log
    enabled: true
    paths:
        - \FSEBroker\*.*
      

output.elasticsearch:
  hosts: ["127.0.0.1:5044"]
  protocol: "http"
  #index: "fss2-%{+yyyy.MM.d

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 15, 2022, 12:22pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/9 "2022-10-15T12:22:39Z")

</div>

> [@Nikolas1306](#):
>
> ```auto
> output.elasticsearch:
> hosts: ["127.0.0.1:5044"]
> protocol: "http"
> 
> ```

This is for sending it to Elasticsearch, which you are not doing. Instead configure it to [send data to Logstash](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html).

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 12:27pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/10 "2022-10-15T12:27:44Z")

</div>

sorry but if i change the config with

```auto
input {
    tcp {
        port => 5000
        type => syslog
        codec => json_lines
    }
}

```

in this case work but file log is not json in this case

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 12:30pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/11 "2022-10-15T12:30:57Z")

</div>

difference in logstash log with config tcp

`[2022-10-15T12:29:20,826][INFO][logstash.inputs.tcp][terza][02b3dac46b0b3d31eabbcf551e1292d22db8816cf5436cbcac98af1463933661] Starting tcp input listener {:address=>"0.0.0.0:5044", :ssl_enable=>false}`

and

`[2022-10-15T12:15:06,822][INFO][org.logstash.beats.Server][terza][0bc359621600c3614b91a3cd92e6ee0d262ea0ed4fe2b06cfcd2d59f46baf37f] Starting server on port: 5044`

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 12:40pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/12 "2022-10-15T12:40:14Z")

</div>

if use tcp index is 8k but original file send is 20mega

```auto
input {
    tcp {
        port => 5044
        #type => syslog
        #codec => json_lines
    }
}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a143d52a043969e5821c2f2f6d6914807c6d3240.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 15, 2022, 1:36pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/13 "2022-10-15T13:36:57Z")

</div>

You should use the `beats` input and configure your filebeat to use the logstash output, anything else will not work as expected.

Beats use a custom protocol over tcp, so a TCP input will not work for beats messages.

You need to have only this output in your filebeat:

```auto
output.logstash:
  hosts: ["127.0.0.1:5044"]

```

And you need to have only this input in your configuration:

```auto
input {
    beats {
      host => "localhost"
      port => 5044
    }
}

```

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 1:50pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/14 "2022-10-15T13:50:02Z")

</div>

> [@leandrojmp](#):
>
> ```auto
> input {
> beats {
> host => "localhost"
> port => 5044
> }
> }
> 
> ```

yes sorry is different

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 1:59pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/15 "2022-10-15T13:59:24Z")

</div>

is possible use multiline config?

```auto
input {
    beats {
      host => "localhost"
      port => 5044
    }
    
    codec => multiline {
              pattern => "^%{TIMESTAMP_ISO8601} "
              negate => true
              what => "previous"
        }
}

output {

		elasticsearch {
			hosts => ["localhost:9200"]
			index => "fss_1"
		}
		

		stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 15, 2022, 2:05pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/16 "2022-10-15T14:05:11Z")

</div>

If you need multiline you need to configure it in Filebeat, not Logstash, configuring multiline in Logstash for messages sent by filebeat will not work.

Check the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html)

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 15, 2022, 2:07pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/17 "2022-10-15T14:07:06Z")

</div>

> [@leandrojmp](#):
>
> Se hai bisogno di multiline devi configurarlo in Filebeat, non logstash, la configurazione multilinea in Logstash per i messaggi inviati da filebeat non funzionerà.

ok tnx very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2022, 2:07pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681/18 "2022-11-12T14:07:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
