# Is it possible to post JSON to logstash directly outside of a BEAT?

**URL:** <https://discuss.elastic.co/t/is-it-possible-to-post-json-to-logstash-directly-outside-of-a-beat/185436>\
**Category:** Logstash\
**Created:** [June 12, 2019, 2:17pm UTC](https://discuss.elastic.co/t/is-it-possible-to-post-json-to-logstash-directly-outside-of-a-beat/185436 "2019-06-12T14:17:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![raged](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raged/32/45722_2.png) [@raged](https://discuss.elastic.co/u/raged)\
**Post date:** [June 12, 2019, 2:17pm UTC](https://discuss.elastic.co/t/is-it-possible-to-post-json-to-logstash-directly-outside-of-a-beat/185436/1 "2019-06-12T14:17:22Z")

</div>

Good morning,

Does anyone know if it's possible to post data to logstash via something like this:

`invoke-webrequest -uri $uri -ContentType 'application/json' -body $body`

We have our pipeline on logstash listening on port 5044. I know it's also listening on 9600, but I want the events to go through my already defined config for 5044.

Thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 12, 2019, 2:45pm UTC](https://discuss.elastic.co/t/is-it-possible-to-post-json-to-logstash-directly-outside-of-a-beat/185436/2 "2019-06-12T14:45:49Z")

</div>

If you are using an http input then you can do that. If you are using a beats input (which the use of port 5044 suggests) then no, since that speaks lumberjack, not HTTP.

---

<div class="post-metadata">

**Author:** ![raged](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raged/32/45722_2.png) [@raged](https://discuss.elastic.co/u/raged)\
**Post date:** [June 12, 2019, 3:39pm UTC](https://discuss.elastic.co/t/is-it-possible-to-post-json-to-logstash-directly-outside-of-a-beat/185436/3 "2019-06-12T15:39:41Z")

</div>

Thanks Badger.

For anyone else that comes across this post, I ended up having to do a few things on our logstash server config:

First, I edited the **pipelines.yml** in _\etc\logstash\_ to include this text:

```
- pipeline.id: httpbeat
  path.config: "/etc/logstash/conf.d/httpbeat.conf"
  pipeline.batch.size: 125
  pipeline.workers: 2

```

Then, I created a **httpbeat.conf** in _\etc\logstash\config.d\_:

```
input {
	http {
		port => 5045
	}
}

output {
  if "_grokparsefailure" not in [tags] {
	elasticsearch {
		hosts => ["https://ES:9200","https://ES:9200"]
		truststore => "/etc/logstash/certs/cacerts"
		truststore_password => "changeit"
		index => "httpbeat-%{+YYYY.MM.dd}"
		user => USER
		password => PASSWORD
	}
  }
}

```

As a test, some garbage data from powershell\_ise:

```
$data = @()
$num = 1..4 | %{$results = "" | select Name,Time;$results.name=$env:COMPUTERNAME;$results.time=$(get-date -f G);$data+=$results}
$body = ConvertTo-Json $data -Compress
$uri = "http://LS:5045"
Invoke-RestMethod -Method Post -Uri $uri -ContentType 'application/json'-Body $body -ErrorAction Stop

```

And in Kibana I see this was posted:

```
{
  "_index": "httpbeat-2019.06.12",
  "_type": "doc",
  "_id": "ID",
  "_version": 1,
  "_score": null,
  "_source": {
    "@version": "1",
    "@timestamp": "2019-06-12T15:28:49.545Z",
    "Name": "PCNAME",
    "host": "IP",
    "Time": "6/12/2019 10:28:49 AM",
    "headers": {
      "http_user_agent": "Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.17763.503",
      "request_path": "/",
      "http_accept": null,
      "http_host": "LS:5045",
      "content_type": "application/json",
      "content_length": "209",
      "http_version": "HTTP/1.1",
      "request_method": "POST"
    }
  },
  "fields": {
    "@timestamp": [
      "2019-06-12T15:28:49.545Z"
    ]
  },
  "sort": [
    1560353329545
  ]
}

```

Progress, not sure why it didn't include any of the JSON I attempted to post in the body... Badger any ideas?

This is the JSON I tried to post:

> **EDIT**
>
> > [{"Name":"PCNAME","Time":"6/12/2019 10:28:49 AM"},{"Name":"PCNAME","Time":"6/12/2019 10:28:49 AM"},{"Name":"PCNAME","Time":"6/12/2019 10:28:49 AM"},{"Name":"PCNAME","Time":"6/12/2019 10:28:49 AM"}]

This works as expected:

> Invoke-RestMethod -Method Post -Uri $uri -ContentType 'application/json'-Body $((gwmi win32\_computersystem | select Domain,Manufacturer,Model,Name | ConvertTo-Json -Compress)) -ErrorAction Stop

JSON from Kibana:

> {  
> "\_index": "httpbeat-2019.06.12",  
> "\_type": "doc",  
> "\_id": "ID",  
> "\_version": 1,  
> "\_score": null,  
> "\_source": {  
> "@version": "1",  
> "@timestamp": "2019-06-12T15:54:06.141Z",  
> "Manufacturer": "HP",  
> "Name": "PCNAME",  
> "Model": "HP EliteBook 840 G5",  
> "host": "IP",  
> "headers": {  
> "http\_user\_agent": "Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.17763.503",  
> "request\_path": "/",  
> "http\_accept": null,  
> "http\_host": "LS:5045",  
> "content\_type": "application/json",  
> "content\_length": "92",  
> "http\_version": "HTTP/1.1",  
> "request\_method": "POST"  
> },  
> "Domain": "[domain.com](http://domain.com)"  
> },  
> "fields": {  
> "@timestamp": [  
> "2019-06-12T15:54:06.141Z"  
> ]  
> },  
> "sort": [  
> 1560354846141  
> ]  
> }

Thanks again Badger.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2019, 3:39pm UTC](https://discuss.elastic.co/t/is-it-possible-to-post-json-to-logstash-directly-outside-of-a-beat/185436/4 "2019-07-10T15:39:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
