# Logstash is not capturing data from file beat

**URL:** <https://discuss.elastic.co/t/logstash-is-not-capturing-data-from-file-beat/127312>\
**Category:** Logstash\
**Created:** [April 9, 2018, 11:30am UTC](https://discuss.elastic.co/t/logstash-is-not-capturing-data-from-file-beat/127312 "2018-04-09T11:30:11Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [April 9, 2018, 11:30am UTC](https://discuss.elastic.co/t/logstash-is-not-capturing-data-from-file-beat/127312/1 "2018-04-09T11:30:11Z")

</div>

[2018-04-09T16:57:23,836][INFO][org.logstash.beats.BeatsHandler] [local: 192.168.36.198:5044, remote: 192.168.36.37:47240] Handling exception: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 84  
[2018-04-09T16:57:23,836][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.  
io.netty.handler.codec.DecoderException: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 84  
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:459) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.handler.codec.ByteToMessageDecoder.channelInputClosed(ByteToMessageDecoder.java:392) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.handler.codec.ByteToMessageDecoder.channelInputClosed(ByteToMessageDecoder.java:359) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.handler.codec.ByteToMessageDecoder.channelInactive(ByteToMessageDecoder.java:342) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:245) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.channel.AbstractChannelHandlerContext.access$300(AbstractChannelHandlerContext.java:38) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.channel.AbstractChannelHandlerContext$4.run(AbstractChannelHandlerContext.java:236) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.util.concurrent.DefaultEventExecutor.run(DefaultEventExecutor.java:66) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:858) [netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-all-4.1.18.Final.jar:4.1.18.Final]  
at java.lang.Thread.run(Thread.java:748) [?:1.8.0\_161]  
Caused by: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 84  
at org.logstash.beats.BeatsParser.decode(BeatsParser.java:92) ~[logstash-input-beats-5.0.10.jar:?]  
at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:489) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:428) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 9, 2018, 11:44am UTC](https://discuss.elastic.co/t/logstash-is-not-capturing-data-from-file-beat/127312/2 "2018-04-09T11:44:20Z")

</div>

What does your Logstash and Filebeat configurations look like? Make sure you posted them as preformatted text (e.g. using the `</>` toolbar button).

---

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [April 9, 2018, 12:22pm UTC](https://discuss.elastic.co/t/logstash-is-not-capturing-data-from-file-beat/127312/3 "2018-04-09T12:22:46Z")

</div>

Logstash config File:  
input {  
beats {  
port =\> 5044  
type =\> "log"  
}  
}

filter {  
grok {  
match =\> { "source" =\> "%{GREEDYDATA}/%{GREEDYDATA:app}.log" }  
}  
}

output {  
elasticsearch {  
hosts =\> "192.168.36.37:9200"  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
stdout { codec =\> rubydebug }  
}

Filebeat Config file :

#----------------------------- Logstash output --------------------------------  
#output.logstash:

# The Logstash hosts

hosts: ["192.168.36.37:5044"]

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

#=========================== Filebeat prospectors =============================

filebeat.prospectors:

# Each - is a prospector. Most options can be set at the prospector level, so

# you can use different prospectors for various configurations.

# Below are the prospector specific configurations.

- type: log

---

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [April 9, 2018, 12:26pm UTC](https://discuss.elastic.co/t/logstash-is-not-capturing-data-from-file-beat/127312/4 "2018-04-09T12:26:50Z")

</div>

and i can see logstash service running but lot listening on port number 5044 .

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 9, 2018, 1:21pm UTC](https://discuss.elastic.co/t/logstash-is-not-capturing-data-from-file-beat/127312/5 "2018-04-09T13:21:56Z")

</div>

I repeat: Make sure you post them as preformatted text (e.g. using the `</>` toolbar button).

---

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [April 10, 2018, 11:59am UTC](https://discuss.elastic.co/t/logstash-is-not-capturing-data-from-file-beat/127312/6 "2018-04-10T11:59:25Z")

</div>

```
indent preformatted text by 4 spaces

```

Logstash config File:  
input {  
beats {  
port =\> 5044  
type =\> "log"  
}  
}

filter {  
grok {  
match =\> { "source" =\> "%{GREEDYDATA}/%{GREEDYDATA:app}.log" }  
}  
}  
output {  
elasticsearch {  
hosts =\> "192.168.36.37:9200"  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![Nagu\_R\_Pujari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nagu_r_pujari/32/29216_2.png) [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Post date:** [April 10, 2018, 12:00pm UTC](https://discuss.elastic.co/t/logstash-is-not-capturing-data-from-file-beat/127312/7 "2018-04-10T12:00:21Z")

</div>

```
indent preformatted text by 4 spaces

```

Filebeat Config file :

#----------------------------- Logstash output --------------------------------  
#output.logstash:  
The Logstash hosts

hosts: ["192.168.36.37:5044"]  
Optional SSL. By default is off.  
List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]  
Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"  
Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

#=========================== Filebeat prospectors =============================

filebeat.prospectors:  
Each - is a prospector. Most options can be set at the prospector level, so  
you can use different prospectors for various configurations.  
Below are the prospector specific configurations.

```
type: log
Change to true to enable this prospector configuration.

enabled: true
Paths that should be crawled and fetched. Glob based paths.

paths:
    /var/log/*
    #- c:\programdata\elasticsearch\logs
indent preformatted text by 4 spaces
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2018, 12:00pm UTC](https://discuss.elastic.co/t/logstash-is-not-capturing-data-from-file-beat/127312/8 "2018-05-08T12:00:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
