# Logstash output http from a curl command

**URL:** <https://discuss.elastic.co/t/logstash-output-http-from-a-curl-command/228389>\
**Category:** Logstash\
**Created:** [April 16, 2020, 5:53pm UTC](https://discuss.elastic.co/t/logstash-output-http-from-a-curl-command/228389 "2020-04-16T17:53:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 16, 2020, 5:53pm UTC](https://discuss.elastic.co/t/logstash-output-http-from-a-curl-command/228389/1 "2020-04-16T17:53:05Z")

</div>

hi, i need to go from logstash to a web restAPI, i'm having trouble converting a curl command into the output { http {}} format. any suggestions would be appreciated.. there arent many examples..

This is the curl command that works:  
`curl -X PUT "http://192.168.4.148:5000/indicators" -H "accept: application/json" -H "Content-Type: application/json" -d '{"indicator":"%{src_ip}", "group": "everyone", "provider": "laFusionCenter:%{type}", "confidence":"4", "tlp":"green", "count":"%{count}"}'`

I \* **think** \* I’d want to use format “message” and the message being you json string..  
any suggestions or help would be appreciated.

---

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 17, 2020, 2:15pm UTC](https://discuss.elastic.co/t/logstash-output-http-from-a-curl-command/228389/2 "2020-04-17T14:15:57Z")

</div>

I'm closer, but still getting errors, any suggestions would be appreciated  
output {  
elasticsearch {  
hosts =\> ["[http://192.168.4.140:9200](http://192.168.4.140:9200)"]  
index =\> "tpot19-%{+yyyy-MM}"  
}  
http {  
url =\> "[http://csirtg.io/api/users/darrell/feeds/HP19/indicators/](http://csirtg.io/api/users/darrell/feeds/HP19/indicators/)"  
http\_method =\> "post"  
format =\> "json"  
message =\> "{ "indicator": { "indicator": %{src\_ip}, "itype": "ipv4", "description": "tsec honeypot19 - %{type}", "tags": ["honeypot-%{type}"] }}"

```
        headers => {
                "Authorization" => "d82b91dcc2c6190d49c8XXXXXXXXXXXX"
                "accept" => "application/json"
        } #end headers
  }
}
```

---

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 26, 2020, 2:53am UTC](https://discuss.elastic.co/t/logstash-output-http-from-a-curl-command/228389/3 "2020-04-26T02:53:23Z")

</div>

i finally got it.. i needed a "put" not a "post" and my message was off:

```
output {
  elasticsearch {
    hosts => ["http://192.168.4.140:9200"]
    index => "tpot19-%{+yyyy-MM}"
  }
  http {
                url => "http://192.168.4.148:5000/indicators"
                http_method => "put"
                content_type => "application/json"
                format => "message"
                message => '[
                                {
                                        "indicator": "%{src_ip}",
                                        "group": "everyone",
                                        "itype": "ipv4",
                                        "tlp": "green",
                                        "provider": "center",
                                        "confidence": 4,
                                        "tags": %{tags}
                        }
                ]'
                headers => {
                        'Accept' => 'application/json'
                        'Content-type' => 'application/json'
                } #end headers
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2020, 2:53am UTC](https://discuss.elastic.co/t/logstash-output-http-from-a-curl-command/228389/4 "2020-05-24T02:53:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
