# Logstash 1.5.4 Output to Elasticsearch with https

**URL:** <https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065>\
**Category:** Logstash\
**Created:** [March 23, 2021, 9:20am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065 "2021-03-23T09:20:07Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dan4](https://avatars.discourse-cdn.com/v4/letter/d/e9c0ed/32.png) [@Dan4](https://discuss.elastic.co/u/Dan4)\
**Post date:** [March 23, 2021, 9:20am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/1 "2021-03-23T09:20:07Z")

</div>

Hello together,

I am new to the elastic stack and have no further experience than just google a solution. In my environment I have to use Logstash on a remote server. I can not change it. I have no control over the version which is installed. Currently it is Logstash 1.5.4 .

I want to send my log data directly to elasticsearch. Therefore I have to use a https url. Based on the old logstash version (1.5.4), I have no idea how to do it.  
Some weeks ago I was sending my data to a kafka server. This works for me, but now I have different requirments so I have to change the output area of my logstash config to send data to an elastic server.

This is my current logstash configuration:

```auto
output {
		elasticsearch {
			protocol => http
			host => "https://myelasticserver.com"
			port => "443"
			user => "myuser"
			password => mysecretpassword
			index => "classic-dev-%{+YYYY.MM.dd}"
		}
}

```

"host" should be my elasticserver address, which is secured with basic auth.

If I run this script with my actual paramters, I get the following error:  
"Failed to install template: https: Name or service not known {:level=\>:error}"

Thanks for your help in advance.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2021, 9:47am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/2 "2021-03-23T09:47:04Z")

</div>

Logstash 1.5.4 is very old and [not compatible with recent versions](https://www.elastic.co/support/matrix#matrix_compatibility). I suspect you need to either upgrade or use a MQ like Kafka as an intermediate step.

---

<div class="post-metadata">

**Author:** ![Dan4](https://avatars.discourse-cdn.com/v4/letter/d/e9c0ed/32.png) [@Dan4](https://discuss.elastic.co/u/Dan4)\
**Post date:** [March 23, 2021, 9:49am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/3 "2021-03-23T09:49:01Z")

</div>

Thanks for your answer. Is there any chance to use https with the current version 1.5.4?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2021, 9:52am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/4 "2021-03-23T09:52:04Z")

</div>

I do not know. Have not used that version in a long long time.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 23, 2021, 10:26am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/5 "2021-03-23T10:26:18Z")

</div>

What is the elasticsearch version?

---

<div class="post-metadata">

**Author:** ![Dan4](https://avatars.discourse-cdn.com/v4/letter/d/e9c0ed/32.png) [@Dan4](https://discuss.elastic.co/u/Dan4)\
**Post date:** [March 23, 2021, 11:06am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/6 "2021-03-23T11:06:17Z")

</div>

Hello, currently i am using

```auto
  "version" : {
    "number" : "7.9.3",
    ...

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 23, 2021, 11:40am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/7 "2021-03-23T11:40:12Z")

</div>

This is not going to work IMO.

You need to use the same major version (even better the same exact version). So if you want to use LS 1.5, use Elasticsearch 1.5 which I definitely do not recommend!

Your best chance IMO is to upgrade LS to 7.9.3.

---

<div class="post-metadata">

**Author:** ![Dan4](https://avatars.discourse-cdn.com/v4/letter/d/e9c0ed/32.png) [@Dan4](https://discuss.elastic.co/u/Dan4)\
**Post date:** [March 23, 2021, 12:01pm UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/8 "2021-03-23T12:01:45Z")

</div>

> [@dadoonet](#):
>
> IMO

Thanks for your help. I dont want to use LS 1.5, but I have no rigths to update it. So is it not possible with these different Versions of LS and ES to connect to eacht other directly (Without MQ like Kafka)?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 23, 2021, 11:49pm UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/9 "2021-03-23T23:49:16Z")

</div>

That might work, but that's an ancient version and it might not work with your Kafka version.

---

<div class="post-metadata">

**Author:** ![Dan4](https://avatars.discourse-cdn.com/v4/letter/d/e9c0ed/32.png) [@Dan4](https://discuss.elastic.co/u/Dan4)\
**Post date:** [March 24, 2021, 7:17am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/10 "2021-03-24T07:17:41Z")

</div>

In my case, I just dont know what I can do anymore. I know my LS version is deprecated but I have no influence on that and cannot change it. I think that LS does not connect to my "https" elasticsearch url. My current error is:

Failed to install template: https: Name or service not known {:level=\>:error}

Further configurations with "ssl =\> ..." bring no added value.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2021, 7:47am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/11 "2021-03-24T07:47:50Z")

</div>

As the bulk API has not changed in a long time I do not see why it would not work. Try with the following settings:

```
output {
		elasticsearch {
			protocol => "http"
            ssl => true
			host => "myelasticserver.com:443"
			user => "myuser"
			password => mysecretpassword
			index => "classic-dev-%{+YYYY.MM.dd}"
		}
}

```

Based on the docs for this old version it seems like the use of the `host` and `port` parameters have changed since then.

---

<div class="post-metadata">

**Author:** ![Dan4](https://avatars.discourse-cdn.com/v4/letter/d/e9c0ed/32.png) [@Dan4](https://discuss.elastic.co/u/Dan4)\
**Post date:** [March 24, 2021, 8:30am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/12 "2021-03-24T08:30:48Z")

</div>

Thanks for your suggestion. I tried this in my environment. Now this error is shown:

Failed to install template: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target {:level=\>:error}  
Logstash startup completed  
Got error to send bulk of actions: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target {:level=\>:error}

Is there a configuration in the LS output area where I can define the certification path?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2021, 9:02am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/13 "2021-03-24T09:02:22Z")

</div>

I do not know as I have not used that version in years.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2021, 9:03am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065/14 "2021-04-21T09:03:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
