# Elasticsearch Input Plugin - Faraday::ConnectionFailed

**URL:** <https://discuss.elastic.co/t/elasticsearch-input-plugin-faraday-connectionfailed/123703>\
**Category:** Logstash\
**Created:** [March 13, 2018, 9:26am UTC](https://discuss.elastic.co/t/elasticsearch-input-plugin-faraday-connectionfailed/123703 "2018-03-13T09:26:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![f.hiekel](https://avatars.discourse-cdn.com/v4/letter/f/d26b3c/32.png) [@f.hiekel](https://discuss.elastic.co/u/f.hiekel)\
**Post date:** [March 13, 2018, 9:26am UTC](https://discuss.elastic.co/t/elasticsearch-input-plugin-faraday-connectionfailed/123703/1 "2018-03-13T09:26:45Z")

</div>

Hey,  
currently i try to execute an aggregation function and wirte the resul back to an index. Therefore I thought it would be a good idea to do it with the elasticserach input plugin to execute the query.

My configuration:  
config.d/test.conf:  
input {  
elasticsearch {  
hosts =\> ["[https://localhost:9200](https://localhost:9200)"]  
index =\> "test"  
ssl =\> true  
ca\_file =\> '/elk/logstash-6.1.2/config/ca.crt'  
query =\> '{ "query: { "match": { "serviceCode": "Test" } } }'  
user =\> "elastic"  
password =\> "xxxxx"  
#schedule =\> "\* \* \* \* \*"  
}  
}

```
output {
  stdout {
    codec => "rubydebug"  
  }
  elasticsearch { 
    hosts => ["https://localhost:9200"]
    index => "test-%{+YYYY-MM-dd}"
    ssl => true
    cacert => '/elk/logstash-6.1.2/config/ca.crt'
    user => elastic
    password => xxxxx
  }
}

```

The Problem:  
if I execute the Query via the curl on the command line: curl -u elastic:xxx --cacert '/elk/logstash-6.1.2/config/ca.crt' -XPOST [https://localhost:9200/test](https://localhost:9200/test) -H'Content-Type: application/json' -d'{ "query": { "match": { "serviceCode": "Test" } } }' everythings works and i become a result.  
But if i do it with the logstash elasticserach input plugin I got the following error:

[2018-03-13T10:05:31,454][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.  
Pipeline\_id:main  
Plugin: \<LogStash::Inputs::Elasticsearch hosts=\>["[https://localhost:9200](https://localhost:9200)"], ssl=\>true, ca\_file=\>"/elk/logstash-6.1.2/config/ca.crt", user=\>"elastic", password=\>, id=\>"8e23d1eb74179097bd3586d920769e0ae59d16adcf229057e3a13cd26e6c9b89", enable\_metric=\>true, codec=\>\<LogStash::Codecs::JSON id=\>"json\_d7659cf1-e712-4ffa-b361-b714c70a4556", enable\_metric=\>true, charset=\>"UTF-8"\>, index=\>"test", query=\>"{ "query":{ "match": { "serviceCode":\ "Test" } }", size=\>1000, scroll=\>"1m", docinfo=\>false, docinfo\_target=\>"@metadata", docinfo\_fields=\>["\_index", "\_type", "\_id"]\>  
Error: 400 "Bad Request"  
Exception: Faraday::ConnectionFailed  
Stack: /elk/logstash-6.1.2/vendor/jruby/lib/ruby/stdlib/net/http/response.rb:120:in `error!'

---

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [March 13, 2018, 1:21pm UTC](https://discuss.elastic.co/t/elasticsearch-input-plugin-faraday-connectionfailed/123703/2 "2018-03-13T13:21:04Z")

</div>

According to [this](https://discuss.elastic.co/t/elasticsearch-input-plugin-not-working-over-ssl/59051/2?u=pjanzen) post the https is not allowed in the hosts field.

Hope this helps you further..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2018, 1:21pm UTC](https://discuss.elastic.co/t/elasticsearch-input-plugin-faraday-connectionfailed/123703/3 "2018-04-10T13:21:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
