# Logstash altering defined Elasticsearch URL

**URL:** <https://discuss.elastic.co/t/logstash-altering-defined-elasticsearch-url/93066>\
**Category:** Logstash\
**Created:** [July 13, 2017, 5:52pm UTC](https://discuss.elastic.co/t/logstash-altering-defined-elasticsearch-url/93066 "2017-07-13T17:52:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chris\_Gatto](https://avatars.discourse-cdn.com/v4/letter/c/7c8e57/32.png) [@Chris\_Gatto](https://discuss.elastic.co/u/Chris_Gatto)\
**Post date:** [July 13, 2017, 5:52pm UTC](https://discuss.elastic.co/t/logstash-altering-defined-elasticsearch-url/93066/1 "2017-07-13T17:52:25Z")

</div>

Hello,

I have my Logstash configured with the following output:

```
output {
    hosts => ["http://myhost/elasticsearch"]
}

```

This is a valid URL, as I can cURL commands to Elasticsearch with it, such as

```
curl "http://myhost/elasticsearch/_cat/indices?v"

```

returns my created indices.

However, when Logstash attempts to create a template, it uses the following URL:

```
http://myhost/_template/logstash

```

when I would expect it to use

```
http://myhost/elasticsearch/_template/logstash

```

It appears that the /elasticsearch portion of my URL is being chopped off. What's going on here? Is "elasticsearch" a reserved word in the URL that is removed? As far as I can tell, when I issue [http://myhost/elasticsearch/elasticsearch](http://myhost/elasticsearch/elasticsearch), it attempts to find an index named "elasticsearch" which leads me to believe it isn't reserved.

Any help would be greatly appreciated, thanks!

- Chris

EDIT:  
I am using Logstash and Elasticsearch 5.0.0

EDIT2:  
I have found the following issue:

> [@Unable to fetch mapping because Kibana requests the wrong URL to ES](https://discuss.elastic.co/t/unable-to-fetch-mapping-because-kibana-requests-the-wrong-url-to-es/87305?source_topic_id=93066):
>
> Hello. I set up Kibana, Logstash and ES using docker-compose. Everything's working fine except that on the "Configure an index pattern" page Kibana can't find the logstash-\* indices. I looked at Kibana logs and noticed that it does this: GET /elasticsearch/logstash-\*/\_mapping/field/\*?\_=1495837868624&ignore\_unavailable=false&allow\_no\_indices=false&include\_defaults=true 404 93ms - 9.0B But gets a 404 because it prefixed the url path with /elasticsearch. However, the indices do exist on this pa…

It seems a similar thing happens when querying Elasticsearch from Kibana; elasticsearch is a Kibana proxy to Elasticsearch. Does this also happen to be the case with Logstash?

EDIT3:

Upon changing the endpoint URL to be

```
http://myhost/myes

```

Logstash is still attempting to access

```
http://myhost/_template/logstash

```

What might be the problem?

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [July 21, 2017, 3:46pm UTC](https://discuss.elastic.co/t/logstash-altering-defined-elasticsearch-url/93066/4 "2017-07-21T15:46:17Z")

</div>

Try using the `proxy` config option.  
Or `proxy` and `path`  
Or `hosts` and `path`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2017, 3:46pm UTC](https://discuss.elastic.co/t/logstash-altering-defined-elasticsearch-url/93066/5 "2017-08-18T15:46:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
