# Export Elasticsearch Data

**URL:** <https://discuss.elastic.co/t/export-elasticsearch-data/383692>\
**Category:** Logstash\
**Created:** [November 26, 2025, 4:17pm UTC](https://discuss.elastic.co/t/export-elasticsearch-data/383692 "2025-11-26T16:17:34Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![DVD\_MNC](https://avatars.discourse-cdn.com/v4/letter/d/f08c70/32.png) [@DVD\_MNC](https://discuss.elastic.co/u/DVD_MNC)\
**Post date:** [November 26, 2025, 4:17pm UTC](https://discuss.elastic.co/t/export-elasticsearch-data/383692/1 "2025-11-26T16:17:34Z")

</div>

Hello guys,

i’m working on a solution which use Elasticsearch as DataLake and export data on an external SIEM.

As first requirement I want leverage elasticsearch capabilities as integration and enrichment, so I cannot export data using output in elastic agent because data will not processed by package pipeline offered by native integration. Then i think to use Logstash using elasticsearch as input; but in this way logstash becomes a single point of failure; how can deploy a solution to address my request (even without Logstash; it’s ok an alternative)? I would like a solution which scales dinamically and avoid sending same data two times
