# How To Output to Amazon Elasticsearch Service

**URL:** <https://discuss.elastic.co/t/how-to-output-to-amazon-elasticsearch-service/101247>\
**Category:** Logstash\
**Created:** [September 20, 2017, 11:24pm UTC](https://discuss.elastic.co/t/how-to-output-to-amazon-elasticsearch-service/101247 "2017-09-20T23:24:34Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdanner](https://avatars.discourse-cdn.com/v4/letter/m/76d3ee/32.png) [@mdanner](https://discuss.elastic.co/u/mdanner)\
**Post date:** [September 20, 2017, 11:24pm UTC](https://discuss.elastic.co/t/how-to-output-to-amazon-elasticsearch-service/101247/1 "2017-09-20T23:24:34Z")

</div>

Hello,

I'm setting up my first ELK stack on AWS. I installed Logstash 5.6.0 on an EC2 instance running Ubuntu 16.04.3 LTS. It was installed using the instructions for Debian/RPM. The input side of things is running fine. Now I want to output to Elasticsearch.

What's the best approach to output to the Amazon Elasticsearch service? Ideally I'd like some clear, easy to understand instructions for a newbie. 🙂

---

<div class="post-metadata">

**Author:** ![Woodford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/woodford/32/9540_2.png) [@Woodford](https://discuss.elastic.co/u/Woodford)\
**Post date:** [September 21, 2017, 5:14pm UTC](https://discuss.elastic.co/t/how-to-output-to-amazon-elasticsearch-service/101247/2 "2017-09-21T17:14:34Z")

</div>

Hey Martin:  
Since you say you're a newbie, I'll assume that you're using AES with default settings, which means you need to 'sign' your requests to AES.

Amazon publishes an output filter plugin for Logstash that handles signing requests and makes it simple: [https://github.com/awslabs/logstash-output-amazon\_es](https://github.com/awslabs/logstash-output-amazon_es)

I haven't used it, so I can't comment on any current "gotchas", but it's actively maintained so you should be able to get help if you need it.

If you do run it successfully, you might want to post your step-by-step details here for the next newbie!

If you have setup AES to allow anonymous access (not recommended) you can configure Logstash outputs yourself. AWS provides simple examples here: [http://docs.aws.amazon.com/elasticsearch-service/latest/developerguide/es-kibana.html#es-managedomains-logstash](http://docs.aws.amazon.com/elasticsearch-service/latest/developerguide/es-kibana.html#es-managedomains-logstash)

For example:

output{  
elasticsearch {  
hosts =\> "[search-logs-demo0-cpxczkdpi4bkb4c44g3csyln5a.us-east-1.es.example.com](http://search-logs-demo0-cpxczkdpi4bkb4c44g3csyln5a.us-east-1.es.example.com)"  
ssl =\> true  
flush\_size =\> 250000  
}  
}

Good luck!

---

<div class="post-metadata">

**Author:** ![mdanner](https://avatars.discourse-cdn.com/v4/letter/m/76d3ee/32.png) [@mdanner](https://discuss.elastic.co/u/mdanner)\
**Post date:** [September 21, 2017, 6:24pm UTC](https://discuss.elastic.co/t/how-to-output-to-amazon-elasticsearch-service/101247/3 "2017-09-21T18:24:36Z")

</div>

Thanks for that, Woodward. I ran into trouble when trying to install the plug in you recommended. Simply put, the instructions on the [README.md](http://README.md) don't work.

Curious, as the Logstash configuration I implemented (Debian/RPM) appears to be the preferred option. Even more curious since the plugin is provided by Amazon, yet their installation instructions don't work and support for the plugin is nonexistent. You'd think they'd make it less difficult to use their ES service! Frustrating...

Correct guidance regarding the installation of the logstash-output-amazon-es plugin would be greatly appreciated. 😊

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 21, 2017, 9:20pm UTC](https://discuss.elastic.co/t/how-to-output-to-amazon-elasticsearch-service/101247/4 "2017-09-21T21:20:34Z")

</div>

You might have better luck using Elastic Cloud, then it's just the standard Elasticsearch output plugin and will work with the latest versions of the Elastic Stack.

---

<div class="post-metadata">

**Author:** ![mdanner](https://avatars.discourse-cdn.com/v4/letter/m/76d3ee/32.png) [@mdanner](https://discuss.elastic.co/u/mdanner)\
**Post date:** [September 21, 2017, 11:14pm UTC](https://discuss.elastic.co/t/how-to-output-to-amazon-elasticsearch-service/101247/5 "2017-09-21T23:14:58Z")

</div>

> [@warkolm](#):
>
> Elastic Cloud

Yes @warkolm, the Elastic Cloud is fantastic! I have some AWS credit, though, so I'm doing it the hard way. 🙂

I get the impression it might be easier just to stand up my own Elasticsearch server in the same VPC as the LogStash server.

Thoughts?

---

<div class="post-metadata">

**Author:** ![mdanner](https://avatars.discourse-cdn.com/v4/letter/m/76d3ee/32.png) [@mdanner](https://discuss.elastic.co/u/mdanner)\
**Post date:** [September 28, 2017, 8:06pm UTC](https://discuss.elastic.co/t/how-to-output-to-amazon-elasticsearch-service/101247/6 "2017-09-28T20:06:13Z")

</div>

I'm pleased to report that I installed the logstash-output-amazon-es plugin successfully. Here are the commands that worked:

```
cd /usr/share/logstash
sudo bin/logstash-plugin install logstash-output-amazon_es

```

It's worth noting that these commands are not documented in the README for this plugin.

[https://github.com/awslabs/logstash-output-amazon\_es/blob/master/README.md](https://github.com/awslabs/logstash-output-amazon_es/blob/master/README.md)

I've made the developers aware of this problem - hopefully they'll update the documentation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 26, 2017, 8:06pm UTC](https://discuss.elastic.co/t/how-to-output-to-amazon-elasticsearch-service/101247/7 "2017-10-26T20:06:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
