# Logstash Throwing Error

**URL:** <https://discuss.elastic.co/t/logstash-throwing-error/127840>\
**Category:** Logstash\
**Created:** [April 12, 2018, 2:37pm UTC](https://discuss.elastic.co/t/logstash-throwing-error/127840 "2018-04-12T14:37:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 12, 2018, 2:37pm UTC](https://discuss.elastic.co/t/logstash-throwing-error/127840/1 "2018-04-12T14:37:25Z")

</div>

Sorry for the vague title, not really sure how to be more specific, below is the error message being logged. This is Elastic Stack 6.2.3 on a Windows server

```
[2018-04-12T02:21:41,279][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
java.io.IOException: An existing connection was forcibly closed by the remote host
	at sun.nio.ch.SocketDispatcher.read0(Native Method) ~[?:1.8.0_162]
	at sun.nio.ch.SocketDispatcher.read(SocketDispatcher.java:43) ~[?:1.8.0_162]
	at sun.nio.ch.IOUtil.readIntoNativeBuffer(IOUtil.java:223) ~[?:1.8.0_162]
	at sun.nio.ch.IOUtil.read(IOUtil.java:192) ~[?:1.8.0_162]
	at sun.nio.ch.SocketChannelImpl.read(SocketChannelImpl.java:380) ~[?:1.8.0_162]
	at io.netty.buffer.PooledUnsafeDirectByteBuf.setBytes(PooledUnsafeDirectByteBuf.java:288) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]
	at io.netty.buffer.AbstractByteBuf.writeBytes(AbstractByteBuf.java:1108) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]
	at io.netty.channel.socket.nio.NioSocketChannel.doReadBytes(NioSocketChannel.java:345) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]
	at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:126) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]
	at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:645) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]
	at io.netty.channel.nio.NioEventLoop.processSelectedKeysOptimized(NioEventLoop.java:580) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]
	at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:497) ~[netty-all-4.1.18.Final.jar:4.1.18.Final]
	at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:459) [netty-all-4.1.18.Final.jar:4.1.18.Final]
	at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:858) [netty-all-4.1.18.Final.jar:4.1.18.Final]
	at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-all-4.1.18.Final.jar:4.1.18.Final]
	at java.lang.Thread.run(Thread.java:748) [?:1.8.0_162]

```

My pipeline looks like this:

```
input {
  beats {
    id => "Beats Input"
    port => 5044
    include_codec_tag => false
  }
}
filter {
  if "::ffff:" in [event_data][IpAddress] or "::1" in [event_data][IpAddress]{
    mutate {
      id => "IPv6 Strip"
      gsub => [
        "[event_data][IpAddress]", "::ffff:", "",
        "[event_data][IpAddress]", "::1", ""
      ]
    }
  }
}
output {
  elasticsearch {
    id => "Output to ElasticSearch"
    hosts => "192.168.1.1:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}" 
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2018, 2:37pm UTC](https://discuss.elastic.co/t/logstash-throwing-error/127840/2 "2018-05-10T14:37:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
