# V 6.4. - Invalid Frame Type, received 1

**URL:** <https://discuss.elastic.co/t/v-6-4-invalid-frame-type-received-1/148122>\
**Category:** Logstash\
**Created:** [September 11, 2018, 12:38pm UTC](https://discuss.elastic.co/t/v-6-4-invalid-frame-type-received-1/148122 "2018-09-11T12:38:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sirocco](https://avatars.discourse-cdn.com/v4/letter/s/a88e57/32.png) [@Sirocco](https://discuss.elastic.co/u/Sirocco)\
**Post date:** [September 11, 2018, 12:38pm UTC](https://discuss.elastic.co/t/v-6-4-invalid-frame-type-received-1/148122/1 "2018-09-11T12:38:18Z")

</div>

Hello, I have an issue with logstash:

Versions: elasticsearch-6.4.0-1.noarch, kibana-6.4.0-1.x86\_64, logstash-6.4.0-1.noarch

The log:

` \< [2018-09-11T11:22:42,976][INFO][logstash.pipeline] Pipeline has terminated {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x6d8f95d2 run\>"}  
[2018-09-11T14:02:59,840][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.4.0"}  
[2018-09-11T14:03:05,682][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>1, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2018-09-11T14:03:06,857][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://10.60.192.52:9200/](http://10.60.192.52:9200/)]}}  
[2018-09-11T14:03:06,961][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://10.60.192.52:9200/](http://10.60.192.52:9200/), :path=

> "/"}  
> [2018-09-11T14:03:07,387][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://10.60.192.52:9200/](http://10.60.192.52:9200/)"}  
> [2018-09-11T14:03:07,551][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
> [2018-09-11T14:03:07,575][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
> [2018-09-11T14:03:07,624][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::Elasticsearch", :hosts=\>["[http://10.60.192.52:9200](http://10.60.192.52:9200)"]}  
> [2018-09-11T14:03:07,684][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
> [2018-09-11T14:03:07,773][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh  
> \_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}  
> }}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "prop  
> erties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{  
> "type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
> [2018-09-11T14:03:09,115][INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=\>"0.0.0.0:5044"}  
> [2018-09-11T14:03:09,155][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x5979a392 run\>"}  
> [2018-09-11T14:03:09,361][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
> [2018-09-11T14:03:09,657][INFO][org.logstash.beats.Server] Starting server on port: 5044  
> [2018-09-11T14:03:10,252][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
> [2018-09-11T14:03:45,572][INFO][org.logstash.beats.BeatsHandler] [local: 10.60.192.52:5044, remote: 10.60.194.36:58304] Handling exception: org.logstash.beats.BeatsParser$InvalidFramePro  
> tocolException: Invalid Frame Type, received: 3  
> [2018-09-11T14:03:45,575][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handl  
> er in the pipeline did not handle the exception.  
> io.netty.handler.codec.DecoderException: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 3  
> at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:459) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
> at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:265) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.access$600(AbstractChannelHandlerContext.java:38) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
> at io.netty.channel.AbstractChannelHandlerContext$7.run(AbstractChannelHandlerContext.java:353) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
> at io.netty.util.concurrent.DefaultEventExecutor.run(DefaultEventExecutor.java:66) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
> at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:858) [netty-all-4.1.18.Final.jar:4.1.18.Final]  
> at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-all-4.1.18.Final.jar:4.1.18.Final]  
> at java.lang.Thread.run(Thread.java:748) [?:1.8.0\_181]  
> Caused by: org.logstash.beats.BeatsParser$InvalidFrameProtocolException: Invalid Frame Type, received: 3  
> at org.logstash.beats.BeatsParser.decode(BeatsParser.java:92) ~[logstash-input-beats-5.1.6.jar:?]  
> at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:489) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
> at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:428) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
> ... 8 more /\> `

The conf file:

[root@elk\_server ~]# cat /etc/logstash/logstash.yml |grep -v '#'  
path.data: /elk/logstash

## path.logs: /var/log/logstash

[root@elk\_server ~]# cat /etc/logstash/conf.d/\*.conf  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGLINE}" }  
}  
date {  
match =\> ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
input {  
beats {  
port =\> 5044  
}  
}  
output {  
elasticsearch {  
hosts =\> ["[http://10.60.192.52:9200](http://10.60.192.52:9200)"]  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

The filebeat conf on client:

root@😕 # cat filebeat.yml |grep -v '#'

filebeat:  
prospectors:  
-  
paths:  
- /var/log/_.log  
- /var/log/zabbix/_.log  
- /var/log/syslog  
- /var/log/postgres/_.log  
- /opt/apache-tomcat-7.0.82/logs/_.log  
- /opt/apache-tomcat-6.0.9/logs/_.log  
- /opt/alfresco/tomcat/logs/_.log

```
  input_type: log

```

Could you help me, please?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2018, 12:39pm UTC](https://discuss.elastic.co/t/v-6-4-invalid-frame-type-received-1/148122/2 "2018-10-09T12:39:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
