# Logstash Output Elasticsearch bulk\_path

**URL:** <https://discuss.elastic.co/t/logstash-output-elasticsearch-bulk-path/117031>\
**Category:** Logstash\
**Created:** [January 25, 2018, 11:15am UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-bulk-path/117031 "2018-01-25T11:15:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![TclasenITVT](https://avatars.discourse-cdn.com/v4/letter/t/c6cbf5/32.png) [@TclasenITVT](https://discuss.elastic.co/u/TclasenITVT)\
**Post date:** [January 25, 2018, 11:15am UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-bulk-path/117031/1 "2018-01-25T11:15:08Z")

</div>

Maybe I just don't understood the [Documentation](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-bulk_path) of bulk\_path but as I understood you would use bulk\_path to specifiy the index and then logstash automatically appends /\_bulk. I noticed running Logstash 6.1.1 and Elasticsearch Output 9.0.2 that you need to explicitly specify /\_bulk.

> HTTP Path to perform the \_bulk requests to this defaults to a concatenation of the path parameter **and**"\_bulk"

```
output {
  elasticsearch {
			hosts => ["https://elasticsearch:9200/"] 
			bulk_path=> "logstash-preisstaffel/preisstaffel/_bulk"
			}
}

```

Is this a bug or is it working as intended needing to pass **\_bulk** explicitly?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 27, 2018, 9:20pm UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-bulk-path/117031/2 "2018-01-27T21:20:00Z")

</div>

> Maybe I just don't understood the Documentation of bulk\_path but as I understood you would use bulk\_path to specifiy the index and then logstash automatically appends /\_bulk.

No, that's not how the documentation should be interpreted. The full path to the bulk endpoint should be specified, including `_bulk`.

I'd expect it to be _extremely_ rare to have to override this option. Are you sure you need to?

---

<div class="post-metadata">

**Author:** ![TclasenITVT](https://avatars.discourse-cdn.com/v4/letter/t/c6cbf5/32.png) [@TclasenITVT](https://discuss.elastic.co/u/TclasenITVT)\
**Post date:** [January 29, 2018, 9:11am UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-bulk-path/117031/3 "2018-01-29T09:11:06Z")

</div>

I secured my elasticsearch using readonlyrest and the `rest.action.multi.allow_explicit_index: false` option in my elasticsearch.yml. Using this elasticsearch setting you have to set the bulk\_path explicitly via the url and not inside the body of the request. I search the internet how to be able to import data using logstash and a post pointed me to the bulk\_path option. It didn't work though. Still got a Errorcode 400.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 29, 2018, 9:16am UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-bulk-path/117031/4 "2018-01-29T09:16:31Z")

</div>

And what's the error message that came with the 400 response?

---

<div class="post-metadata">

**Author:** ![TclasenITVT](https://avatars.discourse-cdn.com/v4/letter/t/c6cbf5/32.png) [@TclasenITVT](https://discuss.elastic.co/u/TclasenITVT)\
**Post date:** [January 29, 2018, 9:20am UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-bulk-path/117031/5 "2018-01-29T09:20:28Z")

</div>

Logstash just outputted that `[2018-01-24T12:21:17,433][ERROR][logstash.outputs.elasticsearch] Encountered a retryable error. Will Retry with exponential backoff {:code=>400, :url=>"https://localhost:9200/logstash-gasin-preisstaffel/preisstaffel/_bulk"}`.  
Same error without the type in the bulk\_path.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 29, 2018, 10:47am UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-bulk-path/117031/6 "2018-01-29T10:47:25Z")

</div>

Anything interesting logged on the ES side?

---

<div class="post-metadata">

**Author:** ![TclasenITVT](https://avatars.discourse-cdn.com/v4/letter/t/c6cbf5/32.png) [@TclasenITVT](https://discuss.elastic.co/u/TclasenITVT)\
**Post date:** [January 29, 2018, 11:04am UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-bulk-path/117031/7 "2018-01-29T11:04:55Z")

</div>

elasticsearch was running inside of a container and I did a factory reset of docker after the mobylinuxvm stopped responding. This resulted in the destruction of all logs from that test. I could try recreating it today.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2018, 11:05am UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-bulk-path/117031/8 "2018-02-26T11:05:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
