# Log4j Logstash plugin error

**URL:** <https://discuss.elastic.co/t/log4j-logstash-plugin-error/65591>\
**Category:** Logstash\
**Created:** [November 10, 2016, 6:55am UTC](https://discuss.elastic.co/t/log4j-logstash-plugin-error/65591 "2016-11-10T06:55:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![profic](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@profic](https://discuss.elastic.co/u/profic)\
**Post date:** [November 10, 2016, 6:55am UTC](https://discuss.elastic.co/t/log4j-logstash-plugin-error/65591/1 "2016-11-10T06:55:34Z")

</div>

Hi, I am getting

```
[2016-11-09T14:37:28,009][DEBUG][logstash.inputs.log4j] Closing connection {:client=>"172.17.0.1:43658", :exception=>#<IOError: org.apache.log4j.spi.LoggingEvent; class invalid for deserialization>}

```

while sending logs from log4j to logstash using log4j plugin.

Enviroment:

docker image sebp/elk (elk stack 5.0)  
log4j 1.2.17

logstash conf:

```
input {
   log4j {
     mode => "server"
     host => "0.0.0.0"
     port => 4560
     type => "log4j"
   }
 }
 output {
   stdout {
   }
 }

```

log4j.properties:

```
log4j.rootLogger=debug,tcp

log4j.appender.tcp=org.apache.log4j.net.SocketAppender
log4j.appender.tcp.Port=4560
log4j.appender.tcp.RemoteHost=localhost
log4j.appender.tcp.ReconnectionDelay=10000
log4j.appender.tcp.Threshold=info

```

The next wierd thing is that I had to set log.level to debug to see that error message.

Appreciate any help, thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 10, 2016, 7:01am UTC](https://discuss.elastic.co/t/log4j-logstash-plugin-error/65591/2 "2016-11-10T07:01:53Z")

</div>

Probably an incompatibility between the log4j libraries and/or JVMs. I relies on JVM-native Java object serialization and that's not a stable protocol. I suggest you use another method of collecting logs from your Java program.

---

<div class="post-metadata">

**Author:** ![profic](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@profic](https://discuss.elastic.co/u/profic)\
**Post date:** [November 10, 2016, 8:58am UTC](https://discuss.elastic.co/t/log4j-logstash-plugin-error/65591/3 "2016-11-10T08:58:42Z")

</div>

magnusbaeck Could you suggest any methods?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 10, 2016, 9:25am UTC](https://discuss.elastic.co/t/log4j-logstash-plugin-error/65591/4 "2016-11-10T09:25:47Z")

</div>

- Log as JSON to a file and use Filebeat to ship it. This is the most reliable method but makes a somewhat more complicated deployment.
- Send logs as JSON via UDP.
- Send logs as JSON via TCP.

---

<div class="post-metadata">

**Author:** ![profic](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@profic](https://discuss.elastic.co/u/profic)\
**Post date:** [November 10, 2016, 9:59am UTC](https://discuss.elastic.co/t/log4j-logstash-plugin-error/65591/5 "2016-11-10T09:59:51Z")

</div>

Will try, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2016, 10:00am UTC](https://discuss.elastic.co/t/log4j-logstash-plugin-error/65591/6 "2016-12-08T10:00:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
