# Logstash not pushing data to AWS Elasticsearch endpoint

**URL:** <https://discuss.elastic.co/t/logstash-not-pushing-data-to-aws-elasticsearch-endpoint/138669>\
**Category:** Logstash\
**Created:** [July 5, 2018, 8:36am UTC](https://discuss.elastic.co/t/logstash-not-pushing-data-to-aws-elasticsearch-endpoint/138669 "2018-07-05T08:36:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shweta\_Priyadarshani](https://avatars.discourse-cdn.com/v4/letter/s/ecae2f/32.png) [@Shweta\_Priyadarshani](https://discuss.elastic.co/u/Shweta_Priyadarshani)\
**Post date:** [July 5, 2018, 8:36am UTC](https://discuss.elastic.co/t/logstash-not-pushing-data-to-aws-elasticsearch-endpoint/138669/1 "2018-07-05T08:36:54Z")

</div>

Hi all,  
I am trying to push my logs from logstash to elasticsearch but its failing. here is my logstash.conf file :

```
        input {
        		file {
        				path => "D:/shweta/ELK_poc/test3.txt"
        				start_position => "beginning"
        				sincedb_path => "NUL"
        				ignore_older => 0
        			}}

        output {
            elasticsearch {
                hosts => ["https://search-test-domain2-2msy6ufh2vl2ztfulhrtoat6hu.us-west-2.es.amazonaws.com"]
        		index => "testindex4-5july"
        		document_type => "test-file"
            }
        } 

```

The ES endpoint that i have provided in hosts is open , so there should not be an access isssue, but it still gives following error:

```
_[2018-07-05T13:59:05,753][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>https://search-test-domain2-2msy6ufh2vl2ztfulhrtoat6hu.us-west-2.es.amazonaws.com:9200/, :path=>"/"}_
_[2018-07-05T13:59:05,769][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"https://search-test-domain2-2msy6ufh2vl2ztfulhrtoat6hu.us-west-2.es.amazonaws.com:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [https://search-test-domain2-2msy6ufh2vl2ztfulhrtoat6hu.us-west-2.es.amazonaws.com:9200/][Manticore::ResolutionFailure] This is usually a temporary error during hostname resolution and means that the local server did not receive a response from an authoritative server (search-test-domain2-2msy6ufh2vl2ztfulhrtoat6hu.us-west-2.es.amazonaws.com)"}_

```

I am stuck here. But when i downloaded ES and installed it in my machine and ran it locally , with the following logstash.conf file , it worked all good pushing data to local es

```
input {
		file {				
                                path => "D:/shweta/ELK_poc/AEM-error-logs.log"
				start_position => "beginning"
				sincedb_path => "NUL"
				ignore_older => 0
			}
	  }
	  
output {
    elasticsearch {
        hosts => ["localhost:9200"]
    }
}

```

I tried a lot of ways but not able to resolve the issue , can anyone please help. I don't want to give localhost but AWS ES domain endpoint. Any hints or leads will be highly appreciated

Thanks in advance  
Shweta

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 5, 2018, 8:55am UTC](https://discuss.elastic.co/t/logstash-not-pushing-data-to-aws-elasticsearch-endpoint/138669/2 "2018-07-05T08:55:57Z")

</div>

I moved your question to #logstash.

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

BTW did you look at [https://www.elastic.co/cloud](https://www.elastic.co/cloud) and [https://aws.amazon.com/marketplace/pp/B01N6YCISK](https://aws.amazon.com/marketplace/pp/B01N6YCISK) ?

Cloud by elastic is the only way to have access to X-Pack. Think about what is there yet like Security, Monitoring, Reporting and what is coming like Canvas, SQL...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 5, 2018, 9:34am UTC](https://discuss.elastic.co/t/logstash-not-pushing-data-to-aws-elasticsearch-endpoint/138669/3 "2018-07-05T09:34:52Z")

</div>

You need to use the the custom `amazon_es` output plugin.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2018, 9:34am UTC](https://discuss.elastic.co/t/logstash-not-pushing-data-to-aws-elasticsearch-endpoint/138669/4 "2018-08-02T09:34:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
