Winlogbeat flooding logstash with warnings. Handler in the pipeline did not handle the exception. Invalid version of beats protocol

Newbie to ELK stack here. However, I was able to get winlogbeat --> Logstash --> Elastic. I can see winlogbeat data from kibana, but my logs in logstash are flooded with warnings... should there be a concern?


  - name: Application
    ignore_older: 72h
  - name: System
  - name: Security

  enabled: true
  hosts: ["x.x.x.x:5044"]
  index: winlogbeat

logstash has a separate pipeline configured for winlogbeat:

input {
  beats {
   port => 5044

output {
  elasticsearch {
    hosts => ["x.x.x.x:9200"]
    manage_template => false
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"

Logstash logs

[2019-12-20T10:26:49,716][INFO ][][winlogbeat] [local: X.X.X.X:5044, remote: X.X.X.X:63834] Handling exception: Invalid version of beats protocol: 71
[2019-12-20T10:26:49,716][WARN ][][winlogbeat] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
io.netty.handler.codec.DecoderException: Invalid version of beats protocol: 71
	at io.netty.handler.codec.ByteToMessageDecoder.callDecode( ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.channelRead( ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at$600( ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at$ ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.util.concurrent.SingleThreadEventExecutor$ [netty-all-4.1.30.Final.jar:4.1.30.Final]
	at [netty-all-4.1.30.Final.jar:4.1.30.Final]
	at Source) [?:1.8.0_231]
Caused by: Invalid version of beats protocol: 71
	at ~[logstash-input-beats-6.0.3.jar:?]
	at ~[logstash-input-beats-6.0.3.jar:?]
	at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection( ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.callDecode( ~[netty-all-4.1.30.Final.jar:4.1.30.Final]
	... 8 more

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.