# Logstash error - Failed to decode CEF payload. Generating failure event with payload in message field

**URL:** <https://discuss.elastic.co/t/logstash-error-failed-to-decode-cef-payload-generating-failure-event-with-payload-in-message-field/265365>\
**Category:** Logstash\
**Created:** [February 24, 2021, 3:45pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-decode-cef-payload-generating-failure-event-with-payload-in-message-field/265365 "2021-02-24T15:45:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![testsemd\_email](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/testsemd_email/32/82657_2.png) [@testsemd\_email](https://discuss.elastic.co/u/testsemd_email)\
**Post date:** [February 24, 2021, 3:45pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-decode-cef-payload-generating-failure-event-with-payload-in-message-field/265365/1 "2021-02-24T15:45:46Z")

</div>

I configued the syslog.conf file to get the traffic to elasticsearch(installed in same server).

Syslog data traffic is coming as CEF format to logstash.  
syslog.conf file as bellow:

input {  
tcp {  
port =\> 5514  
type =\> "syslog"  
codec =\> cef  
}

}

filter {  
}

output {  
if [type] == "syslog" {  
stdout { codec =\> rubydebug }  
elasticsearch {  
hosts =\> "localhost:9200"  
user =\> "elastic"  
password =\> "XXXXXXX"  
http\_compression =\> "true"  
index =\> "syslog-%{+YYYY.MM.dd}"  
}  
}  
}  
Syslog data traffic is coming to elasticsearch.  
But I got error - Failed to decode CEF payload. Generating failure event with payload in message field  
I'm using ELK 7.10.1 version

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 24, 2021, 4:10pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-decode-cef-payload-generating-failure-event-with-payload-in-message-field/265365/2 "2021-02-24T16:10:11Z")

</div>

What does the message field look like?

---

<div class="post-metadata">

**Author:** ![testsemd\_email](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/testsemd_email/32/82657_2.png) [@testsemd\_email](https://discuss.elastic.co/u/testsemd_email)\
**Post date:** [February 24, 2021, 4:24pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-decode-cef-payload-generating-failure-event-with-payload-in-message-field/265365/3 "2021-02-24T16:24:17Z")

</div>

This is the full error:

[2021-02-24T15:24:52,824][ERROR][logstash.codecs.cef][main][37ba9816c43c43e8bac33efbd4f123f36e0cdadabc1b11535fbd9cbb41dd16ae] Failed to decode CEF payload. Generating failure event with payload in message field. {:exception=\>NoMethodError, :message=\>"undefined method `include?' for nil:NilClass", :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-codec-cef-6.1.1-java/lib/logstash/codecs/cef.rb:306:in `handle'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-codec-cef-6.1.1-java/lib/logstash/codecs/cef.rb:267:in `decode'", "/usr/share/logstash/logstash-core/lib/logstash/codecs/delegator.rb:62:in `block in decode'", "org/logstash/instrument/metrics/AbstractSimpleMetricExt.java:65:in `time'", "org/logstash/instrument/metrics/AbstractNamespacedMetricExt.java:64:in `time'", "/usr/share/logstash/logstash-core/lib/logstash/codecs/delegator.rb:61:in `decode'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-tcp-6.0.6-java/lib/logstash/inputs/tcp.rb:190:in `decode\_buffer'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-tcp-6.0.6-java/lib/logstash/inputs/tcp/decoder\_impl.rb:22:in `decode'"], :data=\>"\<22\>Feb 24 20:54:53 KMG postfix/smtpd[14822]: disconnect from unknown\n\<20\>Feb 24 20:54:53 KMG klms-smtp\_proxy: Unexpected end of SMTP input: Bad file descriptor at void lms::filters::smtp\_proxy::CopySmtpStream(std::istream&, std::ostream&, bool)\n"}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 24, 2021, 4:38pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-decode-cef-payload-generating-failure-event-with-payload-in-message-field/265365/4 "2021-02-24T16:38:36Z")

</div>

> [@testsemd\_email](#):
>
> "undefined method `include?' for nil:NilClass"`

That error is occuring [here](https://github.com/logstash-plugins/logstash-codec-cef/blob/2aa39e986242ea555179f1d1b056878f5081020a/lib/logstash/codecs/cef.rb#L306). I think it is telling you that there is no CEF version header in the message.

```auto
<22>Feb 24 20:54:53 KMG postfix/smtpd[14822]: disconnect from unknown[50.3.251.142]\n<20>Feb 24 20:54:53 KMG klms-smtp_proxy: Unexpected end of SMTP input: Bad file descriptor at void lms::filters::smtp_proxy::CopySmtpStream(std::istream&, std::ostream&, bool)\n"}

```

And indeed, that is a syslog message, but not CEF.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2021, 4:39pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-decode-cef-payload-generating-failure-event-with-payload-in-message-field/265365/5 "2021-03-24T16:39:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
