# Forward Logs from Elasticsearch to external destination application

**URL:** <https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021>\
**Category:** Elasticsearch\
**Created:** [April 22, 2021, 9:31pm UTC](https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021 "2021-04-22T21:31:51Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![vishakh](https://avatars.discourse-cdn.com/v4/letter/v/c89c15/32.png) [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Post date:** [April 22, 2021, 9:31pm UTC](https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021/1 "2021-04-22T21:31:51Z")

</div>

I'm looking to forward already stored logs from Elasticsearch to an external application-source.

We're quite aware that we could leverage Logstash to distribute/split the new future-incoming logs between Elasticsearch and other external destination BUT we would like to forward our already existing logs as-well.

---

<div class="post-metadata">

**Author:** ![vishakh](https://avatars.discourse-cdn.com/v4/letter/v/c89c15/32.png) [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Post date:** [April 22, 2021, 9:32pm UTC](https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021/2 "2021-04-22T21:32:09Z")

</div>

Can anyone please suggest

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 23, 2021, 2:27am UTC](https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021/3 "2021-04-23T02:27:04Z")

</div>

Elasticsearch does not push data. It has a REST endpoint (pull).

You will need to use an additional tool take data from elasticsearch and push it to another destination.

Example, You can use Logstash with elasticsearch as an input and send data / documents to some other destination system.

There are many batch and streaming ETL tools that can use elasticsearch as a source.

---

<div class="post-metadata">

**Author:** ![vishakh](https://avatars.discourse-cdn.com/v4/letter/v/c89c15/32.png) [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Post date:** [April 23, 2021, 2:00pm UTC](https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021/4 "2021-04-23T14:00:09Z")

</div>

While waiting for the response, I did research and go through using Logstash & API's to export logs from Elasticsearch.

As per your response "There are many batch and streaming ETL tools that can use elasticsearch as a source."  
@stephenb Can you please name few ETL tools that can help me achieve this objective? (Are you referring to queuing tools?)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 23, 2021, 2:24pm UTC](https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021/5 "2021-04-23T14:24:53Z")

</div>

Examples I have not looked close at each lately

Logstash  
Stream Sets  
Talend  
Informatica  
Elasticsearch has a JDBC connector so anything that reads JDBC.

---

<div class="post-metadata">

**Author:** ![vishakh](https://avatars.discourse-cdn.com/v4/letter/v/c89c15/32.png) [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Post date:** [April 23, 2021, 6:30pm UTC](https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021/6 "2021-04-23T18:30:54Z")

</div>

Thanks for the response @stephenb  
Considering that we would export the logs from Elasticsearch by any above means, doesn't this impose a overhead on the ELK-Stack? as this would be querying huge amount of data across all the indices

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 23, 2021, 7:18pm UTC](https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021/7 "2021-04-23T19:18:07Z")

</div>

Well sure,

Like any datastore, reads / writes require some level of compute / IO resources nothing is free 🙂

That is why often teams with this use case often split the ingest feed to elasticsearch to both elasticsearch and the other destination at ingest time.

---

<div class="post-metadata">

**Author:** ![vishakh](https://avatars.discourse-cdn.com/v4/letter/v/c89c15/32.png) [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Post date:** [April 27, 2021, 1:59pm UTC](https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021/8 "2021-04-27T13:59:34Z")

</div>

Thank you @stephenb for your response/feedback.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2021, 2:00pm UTC](https://discuss.elastic.co/t/forward-logs-from-elasticsearch-to-external-destination-application/271021/9 "2021-05-25T14:00:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
