# Filebeat - last handler in the pipeline did not handle the exception

**URL:** <https://discuss.elastic.co/t/filebeat-last-handler-in-the-pipeline-did-not-handle-the-exception/147202>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 4, 2018, 12:19pm UTC](https://discuss.elastic.co/t/filebeat-last-handler-in-the-pipeline-did-not-handle-the-exception/147202 "2018-09-04T12:19:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![irom77](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/irom77/32/12976_2.png) [@irom77](https://discuss.elastic.co/u/irom77)\
**Post date:** [September 4, 2018, 12:19pm UTC](https://discuss.elastic.co/t/filebeat-last-handler-in-the-pipeline-did-not-handle-the-exception/147202/1 "2018-09-04T12:19:31Z")

</div>

I am getting below error with filebeat/logstash.

`[2018-09-04T12:05:09,164][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.`

See my config below. I use port 5045, instead default one

```
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - C:\Program Files (x86)\Palo Alto Networks\User-ID Agent\UaDebug.log
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true
  reload.period: 10s
setup.template.settings:
  index.number_of_shards: 3
name: dc
tags: ["user-id"]
env: production
setup.kibana:
output.logstash: 
  hosts: ["1.1.1.1:5045"]

input {
        beats {
                port => 5045
                type => "userid"             
        }
}

filter {

}
output {
        if [type] == "userid" {
                elasticsearch {
                        hosts => "elasticsearch:9200"
                        index => "index-pauserid-%{+YYYY.MM.dd}"
                }                
        }
}
```

---

<div class="post-metadata">

**Author:** ![RobBavey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robbavey/32/20421_2.png) [@RobBavey](https://discuss.elastic.co/u/RobBavey)\
**Post date:** [September 4, 2018, 5:30pm UTC](https://discuss.elastic.co/t/filebeat-last-handler-in-the-pipeline-did-not-handle-the-exception/147202/2 "2018-09-04T17:30:40Z")

</div>

Hi @irom77,

Is there anything else in the log file - any more log entries either above or below that warning? How regularly are you seeing the warning?

The warning is likely benign, but if there is any more information, I can take a look to make sure.

Thanks,

Rob

---

<div class="post-metadata">

**Author:** ![irom77](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/irom77/32/12976_2.png) [@irom77](https://discuss.elastic.co/u/irom77)\
**Post date:** [September 4, 2018, 6:04pm UTC](https://discuss.elastic.co/t/filebeat-last-handler-in-the-pipeline-did-not-handle-the-exception/147202/3 "2018-09-04T18:04:46Z")

</div>

There was this....:  
[2018-09-04T12:36:36,907][INFO][org.logstash.beats.BeatsHandler] [local: 0.0.0.0:5045, remote: 10.41.1.151:64771] Handling exception: Connection timed out  
logstash\_1 | [2018-09-04T12:36:36,908][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.  
logstash\_1 | java.io.IOException: Connection timed out  
logstash\_1 | at sun.nio.ch.FileDispatcherImpl.read0(Native Method) ~[?:1.8.0\_171]  
logstash\_1 | at sun.nio.ch.SocketDispatcher.read(SocketDispatcher.java:39) ~[?:1.8.0\_171]  
logstash\_1 | at sun.nio.ch.IOUtil.readIntoNativeBuffer(IOUtil.java:223) ~[?:1.8.0\_171]  
logstash\_1 | at sun.nio.ch.IOUtil.read(IOUtil.java:192) ~[?:1.8.0\_171]  
logstash\_1 | at sun.nio.ch.SocketChannelImpl.read(SocketChannelImpl.java:380) ~[?:1.8.0\_171]  
logstash\_1 | at io.netty.buffer.PooledUnsafeDirectByteBuf.setBytes(PooledUnsafeDirectByteBuf.java:288) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
logstash\_1 | at io.netty.buffer.AbstractByteBuf.writeBytes(AbstractByteBuf.java:1108) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
logstash\_1 | at io.netty.channel.socket.nio.NioSocketChannel.doReadBytes(NioSocketChannel.java:345) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
logstash\_1 | at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:126) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
logstash\_1 | at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:645) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
logstash\_1 | at io.netty.channel.nio.NioEventLoop.processSelectedKeysOptimized(NioEventLoop.java:580) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
logstash\_1 | at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:497) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]  
logstash\_1 | at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:459) [netty-all-4.1.18.Final.jar:4.1.18.Final]  
logstash\_1 | at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:858) [netty-all-4.1.18.Final.jar:4.1.18.Final]  
logstash\_1 | at io.netty.util.concurrent.FastThreadLocalRunnable

---

<div class="post-metadata">

**Author:** ![RobBavey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robbavey/32/20421_2.png) [@RobBavey](https://discuss.elastic.co/u/RobBavey)\
**Post date:** [September 4, 2018, 6:42pm UTC](https://discuss.elastic.co/t/filebeat-last-handler-in-the-pipeline-did-not-handle-the-exception/147202/4 "2018-09-04T18:42:48Z")

</div>

Hi @irom77

Looks like you are having some connectivity issues between your beats node and Logstash. How often do you see this message in your logstash logs? Are there any errors in the beats logs too?

Thanks,

Rob

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2018, 6:42pm UTC](https://discuss.elastic.co/t/filebeat-last-handler-in-the-pipeline-did-not-handle-the-exception/147202/5 "2018-10-02T18:42:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
