# Logstash and winlogbeat configure SSL, but Logstash print error message :OPENSSL\_internal:WRONG\_VERSION\_NUMBER

**URL:** <https://discuss.elastic.co/t/logstash-and-winlogbeat-configure-ssl-but-logstash-print-error-message-wrong-version-number/229805>\
**Category:** Logstash\
**Created:** [April 26, 2020, 3:31am UTC](https://discuss.elastic.co/t/logstash-and-winlogbeat-configure-ssl-but-logstash-print-error-message-wrong-version-number/229805 "2020-04-26T03:31:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![George\_Wang1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/george_wang1/32/67129_2.png) [@George\_Wang1](https://discuss.elastic.co/u/George_Wang1)\
**Post date:** [April 26, 2020, 3:31am UTC](https://discuss.elastic.co/t/logstash-and-winlogbeat-configure-ssl-but-logstash-print-error-message-wrong-version-number/229805/1 "2020-04-26T03:31:40Z")

</div>

Hi all,

When I configure Logstash and Winlogbeat using SSL, Logstash print error message like that:  
OPENSSL\_internal:WRONG\_VERSION\_NUMBER

Logstash error messages：

BeatsHandler - [local: 0.0.0.0:5044, remote: undefined] Handling exception: javax.net.ssl.SSLHandshakeException: error:100000f7:SSL routines:OPENSSL\_internal:WRONG\_VERSION\_NUMBER  
[WARN] 2020-04-25 20:13:41.342 [nioEventLoopGroup-2-4] DefaultChannelPipeline - An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.

winlogbeat error messages：

2020-04-26T11:02:08.337+0800 ERROR logstash/async.go:256 Failed to publish events caused by: lumberjack protocol error  
2020-04-26T11:02:08.338+0800 ERROR logstash/async.go:256 Failed to publish events caused by: client is not connected  
2020-04-26T11:02:10.066+0800 ERROR pipeline/output.go:121 Failed to publish events: client is not connected  
2020-04-26T11:02:10.066+0800 INFO pipeline/output.go:95 Connecting to backoff(async(tcp://192.168.66.105:5044))  
2020-04-26T11:02:10.143+0800 INFO pipeline/output.go:105 Connection to backoff(async(tcp://192.168.66.105:5044)) established  
2020-04-26T11:02:10.144+0800 INFO [publisher] pipeline/retry.go:196 retryer: send unwait-signal to consumer

---

<div class="post-metadata">

**Author:** ![George\_Wang1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/george_wang1/32/67129_2.png) [@George\_Wang1](https://discuss.elastic.co/u/George_Wang1)\
**Post date:** [April 26, 2020, 3:32am UTC](https://discuss.elastic.co/t/logstash-and-winlogbeat-configure-ssl-but-logstash-print-error-message-wrong-version-number/229805/2 "2020-04-26T03:32:32Z")

</div>

logstash input configuration  
input{  
beats{  
port =\> 5044  
ssl =\> true  
#ssl\_certificate\_authorities =\> ["/etc/logstash/certs/ca.pem"]  
ssl\_certificate =\> "/etc/logstash/certs/logstash.crt"  
ssl\_key =\> "/etc/logstash/certs/logstash.p8"  
#ssl\_verify\_mode =\> "peer"  
#ssl\_verify\_mode =\> "force\_peer"  
#tls\_max\_version =\> 1.2  
#tls\_min\_version =\> 1.2  
}  
syslog{  
port =\> 514  
}  
}

---

<div class="post-metadata">

**Author:** ![George\_Wang1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/george_wang1/32/67129_2.png) [@George\_Wang1](https://discuss.elastic.co/u/George_Wang1)\
**Post date:** [April 26, 2020, 3:33am UTC](https://discuss.elastic.co/t/logstash-and-winlogbeat-configure-ssl-but-logstash-print-error-message-wrong-version-number/229805/3 "2020-04-26T03:33:17Z")

</div>

winlogbeat configuration  
#----------------------------- Logstash output --------------------------------  
output.logstash:

# The Logstash hosts

hosts: ["192.168.66.105:5044"]  
ssl.enabled: true

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

ssl.certificate\_authorities: C:\Program Files\winlogbeat\certs\ca.pem

# Certificate for SSL client authentication

ssl.certificate: C:\Program Files\winlogbeat\certs\winlogbeat.crt

# Client Certificate Key

ssl.key: C:\Program Files\winlogbeat\certs\winlogbeat.key  
verification\_mode : none  
supported\_protocols: "TLSv1.2"

---

<div class="post-metadata">

**Author:** ![George\_Wang1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/george_wang1/32/67129_2.png) [@George\_Wang1](https://discuss.elastic.co/u/George_Wang1)\
**Post date:** [April 26, 2020, 3:33am UTC](https://discuss.elastic.co/t/logstash-and-winlogbeat-configure-ssl-but-logstash-print-error-message-wrong-version-number/229805/4 "2020-04-26T03:33:56Z")

</div>

C:\Program Files\winlogbeat\>winlogbeat.exe test output  
logstash: 192.168.66.105:5044...  
connection...  
parse host... OK  
dns lookup... OK  
addresses: 192.168.66.105  
dial up... OK  
TLS...  
security: server's certificate chain verification is enabled  
handshake... OK  
TLS version: TLSv1.2  
dial up... OK  
talk to server... OK

---

<div class="post-metadata">

**Author:** ![sbagciva](https://avatars.discourse-cdn.com/v4/letter/s/bbe5ce/32.png) [@sbagciva](https://discuss.elastic.co/u/sbagciva)\
**Post date:** [April 27, 2020, 4:36pm UTC](https://discuss.elastic.co/t/logstash-and-winlogbeat-configure-ssl-but-logstash-print-error-message-wrong-version-number/229805/5 "2020-04-27T16:36:06Z")

</div>

any fixes to this yet?? Im having same wrong version issue. but my logs are sending. im seeing them in kibana but im getting this error in logstash log?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2020, 4:36pm UTC](https://discuss.elastic.co/t/logstash-and-winlogbeat-configure-ssl-but-logstash-print-error-message-wrong-version-number/229805/6 "2020-05-25T16:36:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
