# Forward logs from Kafka to Elastic

**URL:** <https://discuss.elastic.co/t/forward-logs-from-kafka-to-elastic/320075>\
**Category:** Elasticsearch\
**Created:** [November 29, 2022, 5:07pm UTC](https://discuss.elastic.co/t/forward-logs-from-kafka-to-elastic/320075 "2022-11-29T17:07:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Deepika1](https://avatars.discourse-cdn.com/v4/letter/d/ad7895/32.png) [@Deepika1](https://discuss.elastic.co/u/Deepika1)\
**Post date:** [November 29, 2022, 5:07pm UTC](https://discuss.elastic.co/t/forward-logs-from-kafka-to-elastic/320075/1 "2022-11-29T17:07:08Z")

</div>

Hello,

I'm trying to forward logs from Kafka machine to Elasticsearch machine using kafka elastic connect referring below document

> **[Kafka Connect Elasticsearch: Kafka Connector Consuming & Indexing - Sematext](https://sematext.com/blog/kafka-connect-elasticsearch-how-to/)**
>
> In the world of DevOps, metric collection, log centralization and analysis Apache Kafka is the most commonly used middleware. More specifically, it is used as a fast, persistent queue between data sources like log shippers and the storage that makes...

configurations are:  
name=elasticsearch-sink  
connector.class=io.confluent.connect.elasticsearch.ElasticsearchSinkConnector  
tasks.max=1  
topics=logs  
topic.index.map=logs:logs\_index  
connection.url=[http://192.168.1.18:9200](http://192.168.1.18:9200) // elasticsearch ip  
type.name=log  
key.ignore=true  
schema.ignore=true

My kafka cluster ip address is : 192.168.1.9 , 192.168.1.10  
However if i'm installing elasticsearch on same machine as kafka and changing connection.url=[http://localhost:9200](http://localhost:9200) i'm able to view index created without any docs in it

Require your assistance  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 30, 2022, 12:53am UTC](https://discuss.elastic.co/t/forward-logs-from-kafka-to-elastic/320075/2 "2022-11-30T00:53:13Z")

</div>

Welcome to our community! 😃

We may not be able to help here as it sounds like kafka isn't sending the data to Elasticsearch, you may need to ask somewhere more kafka specific.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 30, 2022, 7:22am UTC](https://discuss.elastic.co/t/forward-logs-from-kafka-to-elastic/320075/3 "2022-11-30T07:22:53Z")

</div>

Note that this document is quite old. One thing that has changed in Elasticsearch is that document types have been deprecated and removed so it is possible that `type.name=log` is causing problems if you are using a recent version of Elasticsearch. Try removing this or change it to `_doc`. I am not familiar with this connector and it is not supported here, so you may need to reach out to the maintainers or the Kafka community for guidance and compatibility information.

---

<div class="post-metadata">

**Author:** ![Deepika1](https://avatars.discourse-cdn.com/v4/letter/d/ad7895/32.png) [@Deepika1](https://discuss.elastic.co/u/Deepika1)\
**Post date:** [December 15, 2022, 10:10am UTC](https://discuss.elastic.co/t/forward-logs-from-kafka-to-elastic/320075/4 "2022-12-15T10:10:44Z")

</div>

Thank you for your response. I tried with given solution, but it isn't working.  
Do you have any more suggestion?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2023, 10:11am UTC](https://discuss.elastic.co/t/forward-logs-from-kafka-to-elastic/320075/5 "2023-01-12T10:11:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
