# How to use Elasticsearch SQL { XPACK } in Logstash

**URL:** https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995
**Category:** Logstash
**Created:** [October 5, 2020, 1:02pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995 "2020-10-05T13:02:15Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![tusharnemade](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)
#### Post date: [October 5, 2020, 1:02pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995/1 "2020-10-05T13:02:15Z")

</div>

Hello

I am using Logstash 7.8.0 with Elasticsearch v7.8.0.

I am using Logstash to extract data from ES Index-1 and inserting into ES Index-2.

I am not finding a way to use Elasticsearch SQL a part of xpack into Logstash input plugin of elasticsearch.

Could you please help me in this.

Note: I have certain conditions and grok filter is required to split data into respective fields in Index-2 hence I am using logstash.

Thanks  
Tushar Nemade

---

<div class="post-metadata">

### Author: ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)
#### Post date: [October 5, 2020, 1:08pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995/2 "2020-10-05T13:08:25Z")

</div>

Hi,

If you have a [platinum license](https://www.elastic.co/de/subscriptions) you can use the jdbc input plugin of LogStash instead.

Another idea would be to use the [http\_poller plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http_poller.html) and the [SQL REST API](https://www.elastic.co/guide/en/elasticsearch/reference/current/sql-rest-overview.html)

Best regards  
Wolfram

---

<div class="post-metadata">

### Author: ![tusharnemade](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)
#### Post date: [October 5, 2020, 1:10pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995/3 "2020-10-05T13:10:48Z")

</div>

Hi

I do not have Platinum license. Have Basic License.

Can i use these he [http\_poller plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http_poller.html) and the [SQL REST API](https://www.elastic.co/guide/en/elasticsearch/reference/current/sql-rest-overview.html) , with BASIC license.

Thanks  
Tushar Nemade

---

<div class="post-metadata">

### Author: ![tusharnemade](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)
#### Post date: [October 5, 2020, 1:14pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995/4 "2020-10-05T13:14:59Z")

</div>

What i want is : How to specify

"query": "SELECT \* FROM library where timestamp \> somedate"

in logstash input plugin of elasticsearch

Thanks  
Tushar Nemade

---

<div class="post-metadata">

### Author: ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)
#### Post date: [October 6, 2020, 4:59am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995/5 "2020-10-06T04:59:25Z")

</div>

> [@tusharnemade](#):
>
> Can i use these he [http\_poller plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http_poller.html) and the [SQL REST API](https://www.elastic.co/guide/en/elasticsearch/reference/current/sql-rest-overview.html) , with BASIC license.

The Elasticsearch SQL-APIs are part of the Basic license

---

<div class="post-metadata">

### Author: ![tusharnemade](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)
#### Post date: [October 6, 2020, 5:22am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995/6 "2020-10-06T05:22:18Z")

</div>

Okay .. Thanks for your response ..

How to specify

"query": "SELECT \* FROM library where timestamp \> somedate"

in logstash input plugin of elasticsearch

---

<div class="post-metadata">

### Author: ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)
#### Post date: [October 6, 2020, 5:25am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995/7 "2020-10-06T05:25:35Z")

</div>

Please have a look here which had a similar request: [Logstash http\_poller POST Syntax](https://discuss.elastic.co/t/logstash-http-poller-post-syntax/51674/2)

---

<div class="post-metadata">

### Author: ![tusharnemade](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)
#### Post date: [October 6, 2020, 5:29am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995/8 "2020-10-06T05:29:19Z")

</div>

Okay , Thanks. I will check and update in here...

Thanks  
Tushar Nemade

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 3, 2020, 5:29am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-sql-xpack-in-logstash/250995/9 "2020-11-03T05:29:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
