# Logstash intergation with AWS Elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-intergation-with-aws-elasticsearch/36623>\
**Category:** Logstash\
**Created:** [December 8, 2015, 11:39am UTC](https://discuss.elastic.co/t/logstash-intergation-with-aws-elasticsearch/36623 "2015-12-08T11:39:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Siddharth](https://avatars.discourse-cdn.com/v4/letter/s/f19dbf/32.png) [@Siddharth](https://discuss.elastic.co/u/Siddharth)\
**Post date:** [December 8, 2015, 11:39am UTC](https://discuss.elastic.co/t/logstash-intergation-with-aws-elasticsearch/36623/1 "2015-12-08T11:39:44Z")

</div>

Hello,

I am using AWS Elasticsearch service to configure Elasticsearch Cluster and there is a separate server where I have installed Logstash 2.1.0

Here is my Logstash sample configuration file :-

```
input {
    file {
    path => "/var/log/httpd/access_log"
    type => "apache-access"
    start_position => "beginning"
  }
}
filter {
  if [type] == "apache-access" {
grok {
  match => ["message", "%{COMBINEDAPACHELOG}"]
}
  }
}
output {
  elasticsearch {
  hosts => "xxxx-yyyy-oul45pxbkudcpzz7w7l5222od4.us-east-1.es.amazonaws.com:443"
  ssl => "true"
  manage_template => false
  }
}

```

I cannot see any Indices in AWS Elasticsearch.  
I am not sure if I am missing something. Configuration seems to be plain and simple.  
Also there is no log generated on Logstash server.

When I issue the command `/bin/logstash -f 01-logstash.conf` it gives me proper output. This seems Logstash is working but not sending data to AWS Elasticsearch Cluster.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 8, 2015, 6:16pm UTC](https://discuss.elastic.co/t/logstash-intergation-with-aws-elasticsearch/36623/2 "2015-12-08T18:16:14Z")

</div>

Is new data being added to the log file you're monitoring? `start_position => "beginning"` only matters for previously unseen files.

Cranking up the log level with `--verbose` or `--debug` could give additional clues.

---

<div class="post-metadata">

**Author:** ![Siddharth](https://avatars.discourse-cdn.com/v4/letter/s/f19dbf/32.png) [@Siddharth](https://discuss.elastic.co/u/Siddharth)\
**Post date:** [December 9, 2015, 5:40am UTC](https://discuss.elastic.co/t/logstash-intergation-with-aws-elasticsearch/36623/3 "2015-12-09T05:40:06Z")

</div>

Hey @magnusbaeck thanks for your reply. I solved the problem. There was permission issue, we need to provide proper IAM Policies for AWS Elasticsearch Cluster. Now every thing is working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:19am UTC](https://discuss.elastic.co/t/logstash-intergation-with-aws-elasticsearch/36623/4 "2017-07-06T05:19:26Z")

</div>


