# Logstash output Elastic App Search plugin

**URL:** <https://discuss.elastic.co/t/logstash-output-elastic-app-search-plugin/366884>\
**Category:** Logstash\
**Created:** [September 20, 2024, 2:43pm UTC](https://discuss.elastic.co/t/logstash-output-elastic-app-search-plugin/366884 "2024-09-20T14:43:00Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sanjay\_Samanaboina](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sanjay_samanaboina/32/134354_2.png) [@Sanjay\_Samanaboina](https://discuss.elastic.co/u/Sanjay_Samanaboina)\
**Post date:** [September 20, 2024, 2:43pm UTC](https://discuss.elastic.co/t/logstash-output-elastic-app-search-plugin/366884/1 "2024-09-20T14:43:00Z")

</div>

Hi,

We have an application which reads emails and store it in Elastic Search using App search Engine where it is working previously with 7.17 Logstash version which is unable to connect to App search with newer versions of Logstash. Our Logstash output configuration is as below,

```auto
output {
 	elastic_app_search {
		id	=>	"xxx-prod"
		url	=>	"https://xxx-prod.ent.xxx.aws.found.io"
		path	=> "/api/as/v1/"
		engine	=>	"default"
		api_key	=>	"private-key
		document_id => "%{xxxx}"
    timestamp_destination	=>	"sent_date"
	}

```

But I have seen that,

- [**BREAKING**] Swiftype endpoints are no longer supported for both plugins App Search and Workplace Search. The App Search deprecated options `host` and `path` were removed.

since 8.11 version, path option is removed for which I am getting error when I tried to use the configuration with recent Logstash versions and also it is not working if I remove path.

url =\> "[https://xxx-prod.ent.xxx.aws.found.io](https://xxx-prod.ent.xxx.aws.found.io)"

I tried adding /api/v1/engines or /api/v1/ also didn't work where it gave 401 & 404 errors.

][ERROR][logstash.javapipeline][xxx] Pipeline error {:pipeline\_id=\>"xxx", :exception=\>#\<LogStash::ConfigurationError: Failed to connect to App Search. Please check your credentials. Error: [401] {"error":"You need to sign in before continuing."}\>

Link for Reference:

> <https://github.com/logstash-plugins/logstash-integration-elastic_enterprise_search/pull/18>
>
> \<!-- Type of change
> Please label this PR with the release version and one of th…e following labels, depending on the scope of your change:
> \- bug
> \- enhancement
> \- breaking change
> \- doc
> \--\>
> 
> \## Release notes
> 
> 
> \- Updated Enterprise Search clients to version \`\>= 7.16\`, \`\< 9\`, adding also support to the following SSL configurations: \`ssl\_certificate\_authorities\`, \`ssl\_truststore\_path\`, \`ssl\_truststore\_password\`, \`ssl\_truststore\_type\`, \`ssl\_verification\_mode\`, \`ssl\_supported\_protocols\` and \`ssl\_cipher\_suites\`.
> - \[\*\*BREAKING\*\*\] Swiftype endpoints are no longer supported for both plugins App Search and Workplace Search. The App Search deprecated options \`host\` and \`path\` were removed.
> \- Fixed the \`sprintf\` format support for the Workplace Search \`source\` configuration
> 
> \## What does this PR do?
> 
> \<!-- Mandatory
> Explain here the changes you made on the PR. Please explain the WHAT: patterns used, algorithms implemented, design architecture, message processing, etc.
> 
> Example:
> Expose 'xpack.monitoring.elasticsearch.proxy' in the docker environment variables and update logstash.yml to surface this config option.
>   
> This commit exposes the 'xpack.monitoring.elasticsearch.proxy' variable in the docker by adding it in env2yaml.go, which translates from
> being an environment variable to a proper yaml config.
>   
> Additionally, this PR exposes this setting for both xpack monitoring & management to the logstash.yml file.
> \--\>
> 
> \## Why is it important/What is the impact to the user?
> 
> \<!-- Mandatory
> Explain here the WHY or the IMPACT to the user, or the rationale/motivation for the changes.
> 
> Example:
> This PR fixes an issue that was preventing the docker image from using the proxy setting when sending xpack monitoring information.
> and/or
> This PR now allows the user to define the xpack monitoring proxy setting in the docker container.
> \--\>
> 
> \## Checklist
> 
> \<!-- Mandatory
> Add a checklist of things that are required to be reviewed in order to have the PR approved
> 
> List here all the items you have verified BEFORE sending this PR. Please DO NOT remove any item, striking through those that do not apply. (Just in case, strikethrough uses two tildes. ~~Scratch this.~~ )
> \--\>
> 
> \- \[x\] My code follows the style guidelines of this project
> \- \[x\] I have commented my code, particularly in hard-to-understand areas
> \- \[x\] I have made corresponding changes to the documentation
> \- \[x\] I have made corresponding change to the default configuration files (and/or docker env variables)
> \- \[x\] I have added tests that prove my fix is effective or that my feature works
> 
> \## Related issues
> 
> \<!-- Recommended
> Link related issues below. Insert the issue link or reference after the word "Closes" if merging this should automatically close it.
> 
> \- Closes #123
> \- Relates #123
> \- Requires #123
> \- Superseeds #123
> \--\>
> \- Closes https://github.com/elastic/logstash/issues/15114

Is anyone familiar with this issue?
