# Logstash elasticsearch input snapshot

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-input-snapshot/150238>\
**Category:** Logstash\
**Created:** [September 27, 2018, 6:10pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-snapshot/150238 "2018-09-27T18:10:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [September 27, 2018, 6:10pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-snapshot/150238/1 "2018-09-27T18:10:33Z")

</div>

We are trying to input elasticsearch snapshots to logstash to support a dashboard on kibana to display elasticsearch cluster snapshots. Below is not working. No error just no index gets created. The curl command does produce results. We verified specifying another index and query does work.

input {  
elasticsearch {  
hosts =\> "_._._._:9200/\_snapshot/production-elasticsearch2-bck/\_all"  
}  
}

output {  
elasticsearch {  
hosts =\> ["_._._._.\*:9200"]  
index =\> "elasticsearch-backup"  
document\_type =\> "backup"  
document\_id =\> "rrc102-production"  
}  
}

curl 'http://_._._._.\*:9200/\_snapshot/production-elasticsearch2-bck/\_all'

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 27, 2018, 6:18pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-snapshot/150238/2 "2018-09-27T18:18:05Z")

</div>

You can't use the elasticsearch input like that. To make arbitrary HTTP requests you can use the http\_poller input.

---

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [September 27, 2018, 6:20pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-snapshot/150238/3 "2018-09-27T18:20:50Z")

</div>

Got it, looking now..

---

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [September 27, 2018, 6:51pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-snapshot/150238/4 "2018-09-27T18:51:36Z")

</div>

Hitting a required input but docs do not indicate required correct? logstash version 6.3

[2018-09-27T14:37:19,381][ERROR][logstash.inputs.http\_poller] Missing a required setting for the http\_poller input plugin:

input {  
http\_poller {  
schedule =\> # SETTING MISSING  
...  
}  
}

input {  
http\_poller {  
urls =\> {  
test1 =\> "http://_._._._:9200"  
test2 =\> {  
# Supports all options supported by ruby's Manticore HTTP client  
method =\> get  
url =\> "http://_._._._:9200/\_cluster/health"  
headers =\> {  
Accept =\> "application/json"  
}  
}  
}  
request\_timeout =\> 60  
interval =\> 60  
codec =\> "json"  
# A hash of request metadata info (timing, response headers, etc.) will be sent here  
metadata\_target =\> "http\_poller\_metadata"  
}  
}

---

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [September 27, 2018, 7:09pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-snapshot/150238/5 "2018-09-27T19:09:17Z")

</div>

Added the schedule. That will work fine.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2018, 7:09pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-snapshot/150238/6 "2018-10-25T19:09:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
