# \[2025-02-11T15:35:06,661\]\[WARN \]\[o.e.h.AbstractHttpServerTransport\]

**URL:** <https://discuss.elastic.co/t/2025-02-11t1506-661-warn-o-e-h-abstracthttpservertransport/374371>\
**Category:** Elasticsearch\
**Created:** [February 11, 2025, 3:46pm UTC](https://discuss.elastic.co/t/2025-02-11t1506-661-warn-o-e-h-abstracthttpservertransport/374371 "2025-02-11T15:46:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nunex\_17](https://avatars.discourse-cdn.com/v4/letter/n/f17d59/32.png) [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Post date:** [February 11, 2025, 3:46pm UTC](https://discuss.elastic.co/t/2025-02-11t1506-661-warn-o-e-h-abstracthttpservertransport/374371/1 "2025-02-11T15:46:06Z")

</div>

```auto
[2025-02-11T15:35:06,661][WARN][o.e.h.AbstractHttpServerTransport] [timon] caught exception while handling client http traffic, closing connection Netty4HttpChannel{localAddress=/ES-IP:9200, remoteAddress=/Elastalert-IP:36398}
io.netty.handler.codec.PrematureChannelClosureException: Channel closed while still aggregating message
	at io.netty.handler.codec.MessageAggregator.channelInactive(MessageAggregator.java:436) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:303) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:281) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.fireChannelInactive(AbstractChannelHandlerContext.java:274) ~[?:?]
	at io.netty.channel.ChannelInboundHandlerAdapter.channelInactive(ChannelInboundHandlerAdapter.java:81) ~[?:?]
	at io.netty.handler.codec.http.HttpContentDecoder.channelInactive(HttpContentDecoder.java:235) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:303) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:281) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.fireChannelInactive(AbstractChannelHandlerContext.java:274) ~[?:?]
	at io.netty.channel.ChannelInboundHandlerAdapter.channelInactive(ChannelInboundHandlerAdapter.java:81) ~[?:?]
	at org.elasticsearch.http.netty4.Netty4HttpHeaderValidator.channelInactive(Netty4HttpHeaderValidator.java:205) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:303) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:281) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.fireChannelInactive(AbstractChannelHandlerContext.java:274) ~[?:?]
	at io.netty.handler.codec.ByteToMessageDecoder.channelInputClosed(ByteToMessageDecoder.java:412) ~[?:?]
	at io.netty.handler.codec.ByteToMessageDecoder.channelInactive(ByteToMessageDecoder.java:377) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:303) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:281) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.fireChannelInactive(AbstractChannelHandlerContext.java:274) ~[?:?]
	at io.netty.channel.ChannelInboundHandlerAdapter.channelInactive(ChannelInboundHandlerAdapter.java:81) ~[?:?]
	at org.elasticsearch.transport.netty4.Netty4WriteThrottlingHandler.channelInactive(Netty4WriteThrottlingHandler.java:172) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:303) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:281) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.fireChannelInactive(AbstractChannelHandlerContext.java:274) ~[?:?]
	at io.netty.channel.DefaultChannelPipeline$HeadContext.channelInactive(DefaultChannelPipeline.java:1352) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:301) ~[?:?]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelInactive(AbstractChannelHandlerContext.java:281) ~[?:?]
	at io.netty.channel.DefaultChannelPipeline.fireChannelInactive(DefaultChannelPipeline.java:850) ~[?:?]
	at io.netty.channel.AbstractChannel$AbstractUnsafe$7.run(AbstractChannel.java:811) ~[?:?]
	at io.netty.util.concurrent.AbstractEventExecutor.runTask(AbstractEventExecutor.java:173) ~[?:?]
	at io.netty.util.concurrent.AbstractEventExecutor.safeExecute(AbstractEventExecutor.java:166) ~[?:?]
	at io.netty.util.concurrent.SingleThreadEventExecutor.runAllTasks(SingleThreadEventExecutor.java:472) ~[?:?]
	at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:566) ~[?:?]
	at io.netty.util.concurrent.SingleThreadEventExecutor$4.run(SingleThreadEventExecutor.java:997) ~[?:?]
	at io.netty.util.internal.ThreadExecutorMap$2.run(ThreadExecutorMap.java:74) ~[?:?]
	at java.lang.Thread.run(Thread.java:1575) ~[?:?]

```

I have a single node Elasticsearch that is ingesting Suricata logs. In a separate machine i have Elastalert to send alerts to email. I am getting this recorrent "warning" on my elasticsearch.log and can´t figure it out why.

Anyone can help me?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 12, 2025, 8:37am UTC](https://discuss.elastic.co/t/2025-02-11t1506-661-warn-o-e-h-abstracthttpservertransport/374371/2 "2025-02-12T08:37:10Z")

</div>

Looks like it is related to a request from Elastalert. I would recommend checking the logs there for clues/errors.

---

<div class="post-metadata">

**Author:** ![nunex\_17](https://avatars.discourse-cdn.com/v4/letter/n/f17d59/32.png) [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Post date:** [February 17, 2025, 2:43pm UTC](https://discuss.elastic.co/t/2025-02-11t1506-661-warn-o-e-h-abstracthttpservertransport/374371/3 "2025-02-17T14:43:27Z")

</div>

No errors from elastalert side

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [February 17, 2025, 5:21pm UTC](https://discuss.elastic.co/t/2025-02-11t1506-661-warn-o-e-h-abstracthttpservertransport/374371/4 "2025-02-17T17:21:39Z")

</div>

> [@nunex\_17](#):
>
> `remoteAddress=/Elastalert-IP:36398`

The message means that ES started to receive a HTTP request from the client at the given address, but then it saw the connection close before it had received the complete request. Typically that suggests a bug in the client, but it could also be due to a misconfigured network intermediary such as a firewall or router.
