# Logstash Reference - Parsing Logs with Logstash

**URL:** <https://discuss.elastic.co/t/logstash-reference-parsing-logs-with-logstash/129917>\
**Category:** Logstash\
**Created:** [April 28, 2018, 12:25pm UTC](https://discuss.elastic.co/t/logstash-reference-parsing-logs-with-logstash/129917 "2018-04-28T12:25:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![yckoh](https://avatars.discourse-cdn.com/v4/letter/y/b19c9b/32.png) [@yckoh](https://discuss.elastic.co/u/yckoh)\
**Post date:** [April 28, 2018, 12:25pm UTC](https://discuss.elastic.co/t/logstash-reference-parsing-logs-with-logstash/129917/1 "2018-04-28T12:25:41Z")

</div>

Hi, I've tried to send log lines from filebeat to Logstash as per the instructions in the reference. However, even though it shows that the pipeline has started successfully it seems to not give me any output on my command prompt upon logstash -f first-pipeline.conf --config.reload.automatic. What could be the reason? I have attached screens of the command prompt and filebeat.yml file. Any help is much appreciated!

 ![logstash](https://us1.discourse-cdn.com/elastic/original/3X/9/5/952fcf0536a36ba1e5b20500d91658c3e5e2d2ca.jpg)  
 ![filebeat](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8c2ff3b40848a26b50f8662cf02b94c4b176db1d.jpg)  
 ![yml1](https://us1.discourse-cdn.com/elastic/original/3X/6/e/6ee49f6ff89b44c6ea3de090dfddd71a206353b7.jpg)  
 ![yml2](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3db36631796a794ec91b8a84b4effce03456b12e.jpg)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 28, 2018, 3:21pm UTC](https://discuss.elastic.co/t/logstash-reference-parsing-logs-with-logstash/129917/2 "2018-04-28T15:21:21Z")

</div>

Please don't post screenshots when you can copy/paste plain text.

What's the contents of first-pipeline.conf?

---

<div class="post-metadata">

**Author:** ![yckoh](https://avatars.discourse-cdn.com/v4/letter/y/b19c9b/32.png) [@yckoh](https://discuss.elastic.co/u/yckoh)\
**Post date:** [April 28, 2018, 3:41pm UTC](https://discuss.elastic.co/t/logstash-reference-parsing-logs-with-logstash/129917/3 "2018-04-28T15:41:00Z")

</div>

Hi Sir, the contents of first-pipeline.conf are as follows:

input {  
beats {  
port =\> "5044"  
}  
}

# filter {

}  
output {  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 28, 2018, 5:33pm UTC](https://discuss.elastic.co/t/logstash-reference-parsing-logs-with-logstash/129917/4 "2018-04-28T17:33:58Z")

</div>

Okay, so it looks like Filebeat isn't sending anything. Perhaps it has already reached the end of the input file? Can you look in its [registry file](https://www.elastic.co/guide/en/beats/filebeat/current/migration-registry-file.html) to see the current position? Please paste the logs from when Filebeat starts up.

---

<div class="post-metadata">

**Author:** ![yckoh](https://avatars.discourse-cdn.com/v4/letter/y/b19c9b/32.png) [@yckoh](https://discuss.elastic.co/u/yckoh)\
**Post date:** [April 29, 2018, 7:39am UTC](https://discuss.elastic.co/t/logstash-reference-parsing-logs-with-logstash/129917/5 "2018-04-29T07:39:59Z")

</div>

Hi Magnus, here is what I see from the registry file after setting the path to logstash-tutorial.log\* (when it was previously set to logstash-tutorial.log the registry was always empty).  
[{"source":"c:\Users\yckoh\Downloads\logstash-tutorial.log","offset":0,"timestamp":"2018-04-29T15:35:43.6028505+08:00","ttl":-1,"type":"log","FileStateOS":{"idxhi":7733248,"idxlo":817563,"vol":4058132}}]

Thereafter, I get an error when running logstash:  
Sending Logstash's logs to C:/Users/yckoh/Downloads/logstash-6.2.4/logs which is now configured via log4j2.properties  
[2018-04-30T14:35:40,962][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"C:/Users/yckoh/Downloads/logstash-6.2.4/modules/fb\_apache/configuration"}  
[2018-04-30T14:35:41,009][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"C:/Users/yckoh/Downloads/logstash-6.2.4/modules/netflow/configuration"}  
[2018-04-30T14:35:41,212][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-04-30T14:35:41,774][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.2.4"}  
[2018-04-30T14:35:42,562][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2018-04-30T14:35:47,266][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2018-04-30T14:35:50,115][INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=\>"0.0.0.0:5044"}  
[2018-04-30T14:35:50,240][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x3bb0a95a run\>"}  
[2018-04-30T14:35:50,287][INFO][org.logstash.beats.Server] Starting server on port: 5044  
[2018-04-30T14:35:50,396][INFO][logstash.agent] Pipelines running {:count=\>1, :pipelines=\>["main"]}  
[2018-04-30T14:36:20,373][INFO][org.logstash.beats.BeatsHandler] [local: 0:0:0:0:0:0:0:1:5044, remote: 0:0:0:0:0:0:0:1:50829] Handling exception: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 69  
[2018-04-30T14:36:20,373][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.  
io.netty.handler.codec.DecoderException: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 69  
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:459) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:265) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.channel.AbstractChannelHandlerContext.access$600(AbstractChannelHandlerContext.java:38) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.channel.AbstractChannelHandlerContext$7.run(AbstractChannelHandlerContext.java:353) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.util.concurrent.DefaultEventExecutor.run(DefaultEventExecutor.java:66) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:858) [netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-all-4.1.18.Final.jar:4.1.18.Final]  
at java.lang.Thread.run(Unknown Source) [?:1.8.0\_161]  
Caused by: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 69  
at org.logstash.beats.BeatsParser.decode(BeatsParser.java:92) ~[logstash-input-beats-5.0.13.jar:?]  
at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:489) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:428) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
... 8 more  
[2018-04-30T14:36:20,384][INFO][org.logstash.beats.BeatsHandler] [local: 0:0:0:0:0:0:0:1:5044, remote: 0:0:0:0:0:0:0:1:50829] Handling exception: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 84  
[2018-04-30T14:36:20,384][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.  
io.netty.handler.codec.DecoderException: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 84  
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:459) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.handler.codec.ByteToMessageDecoder.channelInputClosed(ByteToMessageDecoder.java:392) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.handler.codec.ByteToMessageDecoder.channelInputClosed(ByteToMessageDecoder.java:359) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.handler.codec.ByteToMessageDecoder.channelInactive(ByteToMessageDecoder.java:342) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:245) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.channel.AbstractChannelHandlerContext.access$300(AbstractChannelHandlerContext.java:38) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.channel.AbstractChannelHandlerContext$4.run(AbstractChannelHandlerContext.java:236) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.util.concurrent.DefaultEventExecutor.run(DefaultEventExecutor.java:66) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:858) [netty-all-4.1.18.Final.jar:4.1.18.Final]  
at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-all-4.1.18.Final.jar:4.1.18.Final]  
at java.lang.Thread.run(Unknown Source) [?:1.8.0\_161]  
Caused by: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 84  
at org.logstash.beats.BeatsParser.decode(BeatsParser.java:92) ~[logstash-input-beats-5.0.13.jar:?]  
at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:489) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 30, 2018, 4:17pm UTC](https://discuss.elastic.co/t/logstash-reference-parsing-logs-with-logstash/129917/6 "2018-04-30T16:17:29Z")

</div>

The `output.logstash:` line in the Filebeat configuration is commented out, so the subsequent `hosts` line is connected to whatever comes before `output.logstash:`. Perhaps an `output.elasticsearch:` line?

---

<div class="post-metadata">

**Author:** ![yckoh](https://avatars.discourse-cdn.com/v4/letter/y/b19c9b/32.png) [@yckoh](https://discuss.elastic.co/u/yckoh)\
**Post date:** [May 2, 2018, 1:39am UTC](https://discuss.elastic.co/t/logstash-reference-parsing-logs-with-logstash/129917/7 "2018-05-02T01:39:01Z")

</div>

Ah yes I missed that. Uncommenting the output.logstash line and commenting the output.elasticsearch line solved the problem. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 30, 2018, 1:39am UTC](https://discuss.elastic.co/t/logstash-reference-parsing-logs-with-logstash/129917/8 "2018-05-30T01:39:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
