# Logstash AWS Elastic Search issue

**URL:** <https://discuss.elastic.co/t/logstash-aws-elastic-search-issue/242164>\
**Category:** Logstash\
**Created:** [July 22, 2020, 9:49am UTC](https://discuss.elastic.co/t/logstash-aws-elastic-search-issue/242164 "2020-07-22T09:49:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ggiff](https://avatars.discourse-cdn.com/v4/letter/g/9dc877/32.png) [@ggiff](https://discuss.elastic.co/u/ggiff)\
**Post date:** [July 22, 2020, 9:49am UTC](https://discuss.elastic.co/t/logstash-aws-elastic-search-issue/242164/1 "2020-07-22T09:49:14Z")

</div>

I have set up Logstash to send user inputs to AWS ElasticSearch, but getting the following issue:

```auto
[WARN] 2020-07-22 09:27:50.704 [Ruby-0-Thread-4: :1] elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"ENDPOINT_URL:443/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=>"Got response code '403' contacting Elasticsearch at URL 'ENDPOINT_URL:443/'"}

```

Elasticsearch instance uses the following access policy:

```auto
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::MYACCOUNT:user/logstash_publisher"
      },
      "Action": "es:*",
      "Resource": "arn:aws:es:eu-west-2:MYACCOUNT:domain/DOMAINNAME/*"
    }
  ]
}

```

and logstash\_publisher has attached also a AmazonESFullAccess policy.

This is the logstash conf file:

```auto
input {
stdin {}
}
output {
stdout {}
amazon_es {
hosts => ["ENDPOINT"]
region => "ENDPOINT-REGION"
index => "stdin-input-logs"
aws_access_key_id => 'LOGPUBLISHER-ACCESS-KEY'
aws_secret_access_key => 'LOGPUBLISHER-SECRET-KEY'
}
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 22, 2020, 11:17am UTC](https://discuss.elastic.co/t/logstash-aws-elastic-search-issue/242164/2 "2020-07-22T11:17:59Z")

</div>

You will need to ask AWS about this sorry. It's a plugin they provide, along with an Elasticsearch service they provide.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2020, 11:18am UTC](https://discuss.elastic.co/t/logstash-aws-elastic-search-issue/242164/3 "2020-08-19T11:18:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
