# Error connecting to secured ES cluster from logstash.filters.elasticsearch

**URL:** <https://discuss.elastic.co/t/error-connecting-to-secured-es-cluster-from-logstash-filters-elasticsearch/179457>\
**Category:** Logstash\
**Created:** [May 3, 2019, 4:20am UTC](https://discuss.elastic.co/t/error-connecting-to-secured-es-cluster-from-logstash-filters-elasticsearch/179457 "2019-05-03T04:20:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![maavericc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maavericc/32/45466_2.png) [@maavericc](https://discuss.elastic.co/u/maavericc)\
**Post date:** [May 3, 2019, 4:20am UTC](https://discuss.elastic.co/t/error-connecting-to-secured-es-cluster-from-logstash-filters-elasticsearch/179457/1 "2019-05-03T04:20:16Z")

</div>

When I am trying to connect to secured ES cluster from logstash.filters.elasticsearch, getting this error: [2019-05-03T04:15:34,613][WARN][logstash.filters.elasticsearch] Failed to query elasticsearch for previous event ... :error=\>"Illegal character in authority at index 8: https://{:host=\>"test-es2:9200", :scheme=\>"https", :protocol=\>"https", :port=\>9200}:9200/indexName/\_search?q=fieldName%3A%2522Field%2520Value%2522&size=1"

Tried ["test-es1:9200"] ["[https://test-es1:9200](https://test-es1:9200)"] ["test-es1"]

elasticsearch {  
ssl =\> "true"  
hosts =\> ["test-es1:9200"]  
ca\_file =\> "/etc/logstash/tls/certs/ca/ca.crt"  
user =\> "user"  
password =\> "pwd"  
index =\> ["indexName"]  
query =\> "query"  
enable\_sort =\> false  
fields =\> {  
field1 =\> field1  
}  
}

Appreciate if someone can help resolve this problem as I am stuck here for last 2 days.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2019, 4:20am UTC](https://discuss.elastic.co/t/error-connecting-to-secured-es-cluster-from-logstash-filters-elasticsearch/179457/2 "2019-05-31T04:20:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
