Moved logstash to 5.0 for just the winlogbeat piece going into our ES cluster. Upgraded cluster from 2.4.0 -> 2.4.1 we'll be moving it to 5.0 next week.
Looks like in the end for some reason pipelining was the issue. Remove that and no timeouts, go figure.