# Logstash error after updating to 7.9.1

**URL:** <https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366>\
**Category:** Logstash\
**Created:** [November 13, 2020, 4:43pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366 "2020-11-13T16:43:37Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![noobman2logstash](https://avatars.discourse-cdn.com/v4/letter/n/f9ae1b/32.png) [@noobman2logstash](https://discuss.elastic.co/u/noobman2logstash)\
**Post date:** [November 13, 2020, 4:43pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366/1 "2020-11-13T16:43:37Z")

</div>

[2020-11-13T16:36:21,302][ERROR][logstash.agent] Failed to execute action {:id=\>:default, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}

please what does this mean ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 13, 2020, 4:47pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366/2 "2020-11-13T16:47:03Z")

</div>

Increase the log.level to debug and see if you get a more informative error message.

---

<div class="post-metadata">

**Author:** ![noobman2logstash](https://avatars.discourse-cdn.com/v4/letter/n/f9ae1b/32.png) [@noobman2logstash](https://discuss.elastic.co/u/noobman2logstash)\
**Post date:** [November 13, 2020, 8:27pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366/3 "2020-11-13T20:27:25Z")

</div>

hi below is what i got

[2020-11-13T20:14:38,120][ERROR][logstash.agent] Failed to execute action {:id=\>:default, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}  
[2020-11-13T20:14:38,612][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2020-11-13T20:14:43,377][INFO][logstash.runner] Logstash shut down.  
[2020-11-13T20:14:43,377][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit  
2020-11-13 20:14:43,378 pool-1-thread-1 DEBUG Stopping LoggerContext[name=277050dc, org.apache.logging.log4j.core.LoggerContext@6b21a869]  
2020-11-13 20:14:43,378 pool-1-thread-1 DEBUG Stopping LoggerContext[name=277050dc, org.apache.logging.log4j.core.LoggerContext@6b21a869]...  
2020-11-13 20:14:43,399 pool-1-thread-1 DEBUG Appender plain\_console stopped with status true  
2020-11-13 20:14:43,399 pool-1-thread-1 DEBUG Shutting down OutputStreamManager SYSTEM\_OUT.false.false  
2020-11-13 20:14:43,399 pool-1-thread-1 DEBUG OutputStream closed  
2020-11-13 20:14:43,399 pool-1-thread-1 DEBUG Shut down OutputStreamManager SYSTEM\_OUT.false.false, all resources released: true  
2020-11-13 20:14:43,399 pool-1-thread-1 DEBUG Appender json\_console stopped with status true  
2020-11-13 20:14:43,330 pool-1-thread-1 DEBUG Stopped org.apache.logging.log4j.core.config.properties.PropertiesConfiguration@687fa4d0 OK  
2020-11-13 20:14:43,330 pool-1-thread-1 DEBUG Stopped LoggerContext[name=277050dc, org.apache.logging.log4j.core.LoggerContext@6b21a869] with status true

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 13, 2020, 8:34pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366/4 "2020-11-13T20:34:32Z")

</div>

The additional messages are not helpful. What does your configuration look like?

---

<div class="post-metadata">

**Author:** ![noobman2logstash](https://avatars.discourse-cdn.com/v4/letter/n/f9ae1b/32.png) [@noobman2logstash](https://discuss.elastic.co/u/noobman2logstash)\
**Post date:** [November 13, 2020, 8:41pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366/5 "2020-11-13T20:41:27Z")

</div>

here is my pipeline config

input {  
#beats - all apps using filebeat logshipper  
beats {  
port =\> 7054  
ssl =\> true  
ssl\_certificate\_authorities =\> ["cert"]  
ssl\_certificate =\> "cert"  
ssl\_key =\> "key"  
ssl\_verify\_mode =\> "peer"  
client\_inactivity\_timeout =\> "006700"  
}  
}  
filter {

grok {  
match =\> { "message" =\> "%{NUMBER:num:float} %{LOGLEVEL:loglevel} [%{DATA:class}]%{GREEDYDATA:message}" }  
}  
if "ERROR" not in [loglevel] {  
drop {}  
}   
mutate  
{  
add\_field =\> {"attlogstashtracker\_appcode" =\> "2pac"}  
}  
}  
output {  
if "2pac-log-windoslogs" in [tags]{  
elasticsearch {  
hosts =\> "host"  
user =\> "{user112}" password =\> "{pass112}"  
index =\> "location-%{+YYYY.MM}"  
manage\_template =\> false  
ssl =\> true  
ssl\_certificate\_verification =\> false  
cacert =\> "/usr/share/logstash/config/cert"  
}  
}  
stdout {  
codec =\> rubydebug  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 13, 2020, 9:02pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366/6 "2020-11-13T21:02:05Z")

</div>

I would try setting

```
ssl => false

```

on the beat input, and commenting out all the other ssl options in the input. See if logstash will then start (if it does you will likely get a lot of `$InvalidFrameProtocolException: Invalid Frame Type, received` exceptions, and obviously you will not get events). If it does start then you have a problem with your certificates or keys (missing private key perhaps?)

Then try the same for the elasticsearch output. Again, you will not get any data into elasticsearch, it is just a way of testing whether the ssl configuration is causing the problem.

---

<div class="post-metadata">

**Author:** ![noobman2logstash](https://avatars.discourse-cdn.com/v4/letter/n/f9ae1b/32.png) [@noobman2logstash](https://discuss.elastic.co/u/noobman2logstash)\
**Post date:** [November 13, 2020, 9:08pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366/7 "2020-11-13T21:08:20Z")

</div>

awesome thanks so much it started. i will check the certs and keys again

---

<div class="post-metadata">

**Author:** ![noobman2logstash](https://avatars.discourse-cdn.com/v4/letter/n/f9ae1b/32.png) [@noobman2logstash](https://discuss.elastic.co/u/noobman2logstash)\
**Post date:** [November 16, 2020, 6:26pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366/8 "2020-11-16T18:26:20Z")

</div>

Hi Badger,

i have fixed the cert but I'm getting another set of errors please see below.

[2020-11-16T18:14:39,338][INFO][org.logstash.beats.BeatsHandler] [local: 0.0.0.0:5506, remote: 10.196.5789.] Handling exception: Connection reset by peer  
[2020-11-16T18:14:39,338][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.  
java.io.IOException: Connection reset by peer  
at sun.nio.ch.FileDispatcherImpl.read0(Native Method) ~[?:?]  
at sun.nio.ch.SocketDispatcher.read(SocketDispatcher.java:39) ~[?:?]  
at sun.nio.ch.IOUtil.readIntoNativeBuffer(IOUtil.java:276) ~[?:?]  
at sun.nio.ch.IOUtil.read(IOUtil.java:233) ~[?:?]  
at sun.nio.ch.IOUtil.read(IOUtil.java:223) ~[?:?]  
at sun.nio.ch.SocketChannelImpl.read(SocketChannelImpl.java:358) ~[?:?]  
at io.netty.buffer.PooledByteBuf.setBytes(PooledByteBuf.java:253) ~[netty-all-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.buffer.AbstractByteBuf.writeBytes(AbstractByteBuf.java:1133) ~[netty-all-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.socket.nio.NioSocketChannel.doReadBytes(NioSocketChannel.java:350) ~[netty-all-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:148) ~[netty-all-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:714) ~[netty-all-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.nio.NioEventLoop.processSelectedKeysOptimized(NioEventLoop.java:650) ~[netty-all-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:576) ~[netty-all-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:493) [netty-all-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor$4.run(SingleThreadEventExecutor.java:989) [netty-all-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.util.internal.ThreadExecutorMap$2.run(ThreadExecutorMap.java:74) [netty-all-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-all-4.1.49.Final.jar:4.1.49.Final]  
at java.lang.Thread.run(Thread.java:834) [?:?]  
[2020-11-16T18:17:02,839][INFO][org.logstash.beats.BeatsHandler] [local: 0.0.0.0:5506, remote: 10.190.581425280] Handling exception: Connection reset by peer  
[2020-11-16T18:17:02,839][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.  
java.io.IOException: Connection reset by peer  
at sun.nio.ch.FileDispatcherImpl.read0(Native Method) ~[?:?]  
at sun.nio.ch.SocketDispatcher.read(SocketDispatcher.java:39) ~[?:?]

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 16, 2020, 6:46pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366/9 "2020-11-16T18:46:07Z")

</div>

So the beat that connected disconnected. Does the log file of the beat give any indication of why?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2020, 6:46pm UTC](https://discuss.elastic.co/t/logstash-error-after-updating-to-7-9-1/255366/10 "2020-12-14T18:46:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
