# Logging events to Logstash via REST with custom request and responses

**URL:** <https://discuss.elastic.co/t/logging-events-to-logstash-via-rest-with-custom-request-and-responses/86031>\
**Category:** Logstash\
**Created:** [May 17, 2017, 2:21am UTC](https://discuss.elastic.co/t/logging-events-to-logstash-via-rest-with-custom-request-and-responses/86031 "2017-05-17T02:21:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dml](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dml](https://discuss.elastic.co/u/dml)\
**Post date:** [May 17, 2017, 2:21am UTC](https://discuss.elastic.co/t/logging-events-to-logstash-via-rest-with-custom-request-and-responses/86031/1 "2017-05-17T02:21:53Z")

</div>

I would like an application to log events to Logstash using a REST API. The request is JSON-encoded event data, some of which are required, some optional, and some would default to default values. The request would need to be processed (perhaps with the help of a filter) and then forwarded to Elasticsearch. When the event is successfully written to Elasticsearch, a JSON-encoded "success" response would be sent back to the application. If any error was encountered during processing (e.g., malformed JSON) or while writing to Elasticsearch (e.g., invalid index provided), a JSON-encoded "failure" response would be sent back to the application.

Is the above use case possible using the existing set of Logstash input, output, and filter plugins? I have read up on logstash-input-http, logstash-output-elasticsearch, and logstash-filter-json. They don't seem to quite do what I am looking for. Should I consider developing custom plugin(s) for this use case? Or put a REST server in between the application and Logstash?

Has anyone done anything similar to this? Any help, suggestions, or examples would be greatly appreciated. Thanks in advance.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 18, 2017, 5:35am UTC](https://discuss.elastic.co/t/logging-events-to-logstash-via-rest-with-custom-request-and-responses/86031/2 "2017-05-18T05:35:12Z")

</div>

> Is the above use case possible using the existing set of Logstash input, output, and filter plugins?

No, sorry. I think you'll have to write a custom script.

While I obviously don't have the full context, I'd have the application write its log events to disk or submit them to a message broker and assume that the messages will be processed.

---

<div class="post-metadata">

**Author:** ![dml](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dml](https://discuss.elastic.co/u/dml)\
**Post date:** [May 19, 2017, 2:27pm UTC](https://discuss.elastic.co/t/logging-events-to-logstash-via-rest-with-custom-request-and-responses/86031/3 "2017-05-19T14:27:25Z")

</div>

Thank you for the quick response. Would you recommend creating a web service(s) and writing directly to Elasticsearch, bypassing Logstash altogether?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 24, 2017, 9:17am UTC](https://discuss.elastic.co/t/logging-events-to-logstash-via-rest-with-custom-request-and-responses/86031/4 "2017-05-24T09:17:47Z")

</div>

If your application really needs to know whether the log entries were successfully written to Elasticsearch that's probably what you'd have to do, but I challenge that premise. Make your application's logging layer as thin, simple, and non-intrusive as possible (i.e. dump everything as JSON to a file) and let another component worry about getting it into Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2017, 9:18am UTC](https://discuss.elastic.co/t/logging-events-to-logstash-via-rest-with-custom-request-and-responses/86031/5 "2017-06-21T09:18:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
