# HTTP input plugin - how to avoid Logstash to pass through preflight OPTIONS to Elasticsearch

**URL:** <https://discuss.elastic.co/t/http-input-plugin-how-to-avoid-logstash-to-pass-through-preflight-options-to-elasticsearch/147462>\
**Category:** Logstash\
**Created:** [September 5, 2018, 6:59pm UTC](https://discuss.elastic.co/t/http-input-plugin-how-to-avoid-logstash-to-pass-through-preflight-options-to-elasticsearch/147462 "2018-09-05T18:59:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tianyid](https://avatars.discourse-cdn.com/v4/letter/t/c89c15/32.png) [@tianyid](https://discuss.elastic.co/u/tianyid)\
**Post date:** [September 5, 2018, 6:59pm UTC](https://discuss.elastic.co/t/http-input-plugin-how-to-avoid-logstash-to-pass-through-preflight-options-to-elasticsearch/147462/1 "2018-09-05T18:59:33Z")

</div>

Hello,

I have web application who is using JQuery Ajax to POST event data of JSON format to Logstash's HTTP input. Here is the snippet of Ajax call.

```
            $.ajax({
                url: logstashUrl,
                method: 'POST',
                dataType: 'json',
                contentType: 'application/json',
                data: JSON.stringify(eventBody),
                success: function() {},
                error: function() {}
             });

```

Logstash then forwards the JSON data to Elasticsearch. Here is the Logstash configuration file:

```
    input {
       http {
          host => "127.0.0.1" # default: 0.0.0.0
          port => 8080 # default: 8080
          response_headers => {
                "Access-Control-Allow-Origin" => "*"
                "Content-Type" => "text/plain"
                "Access-Control-Allow-Headers" => "Origin, X-Requested-With, Content-Type, Accept"
         }
     }
  }
  output {
      elasticsearch {
           hosts => ["localhost:9200"]
      }
  }

```

CORS is enabled in Logstash server side for the cross origin communication. We checked different type of browsers and found in Chrome version 68, there is preflight OPTIONS request sent to Logstash before every POST request and somehow passthrough to Elasticsearch, which is not expected.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/4/74746760be401b41319b2c6c64c5516c8a52a5fa.jpeg)

I made some research and believe it is inevitable to have browser client send preflight to server when across different origin, and one walk-around is to set up "Access-Control-Max-Age" so that response from server can be cached. However it seems not working for me when add `"Access-Control-Max-Age" => 1728000` to input http response header in config file.

Anyone can help?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2018, 6:59pm UTC](https://discuss.elastic.co/t/http-input-plugin-how-to-avoid-logstash-to-pass-through-preflight-options-to-elasticsearch/147462/2 "2018-10-03T18:59:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
