# Logstash output to es

**URL:** <https://discuss.elastic.co/t/logstash-output-to-es/121274>\
**Category:** Logstash\
**Created:** [February 23, 2018, 7:11pm UTC](https://discuss.elastic.co/t/logstash-output-to-es/121274 "2018-02-23T19:11:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![David9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david9/32/42150_2.png) [@David9](https://discuss.elastic.co/u/David9)\
**Post date:** [February 23, 2018, 7:11pm UTC](https://discuss.elastic.co/t/logstash-output-to-es/121274/1 "2018-02-23T19:11:24Z")

</div>

New user of ES Cloud and logstash. I'm told this is where to post such questions...

config is below, nothing's happening (no new data arrives in es). index has been created with mapping.

any suggestions? i'm assuming i've got my parlance wrong.

also where are logs available to see what's going wrong?

thanks

input {  
s3 {  
bucket =\> "com.foobar.abc "  
region =\> "us-east-1"  
access\_key\_id =\> ""  
secret\_access\_key =\> ""  
}  
}  
filter {  
}  
output {  
elasticsearch { hosts =\> ["[https://xxxdb.us-east-1.aws.found.io:9243](https://xxxdb.us-east-1.aws.found.io:9243)"]  
index =\> "test11"  
protocol =\> "http"  
port =\> "9243" }  
}

---

<div class="post-metadata">

**Author:** ![Ranjith\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ranjith_m/32/19272_2.png) [@Ranjith\_M](https://discuss.elastic.co/u/Ranjith_M)\
**Post date:** [February 23, 2018, 8:05pm UTC](https://discuss.elastic.co/t/logstash-output-to-es/121274/2 "2018-02-23T20:05:51Z")

</div>

Hello ,  
Does it have xpack enabled  
Can you share logs after you start Logstash pipeline

---

<div class="post-metadata">

**Author:** ![David9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david9/32/42150_2.png) [@David9](https://discuss.elastic.co/u/David9)\
**Post date:** [February 23, 2018, 8:40pm UTC](https://discuss.elastic.co/t/logstash-output-to-es/121274/3 "2018-02-23T20:40:45Z")

</div>

Thanks, I'm on hosted Elastic Cloud. I'm not seeing anything about how to enable XPack, I thought XPack was pre-installed as part of the cloud service. Specifically, which xpack feature are you asking about.

I'm seeing tons of log files however most are INFO, a couple are WARN, none seem to be related to Logstash.

I'm still feeling my way around the interfaces so maybe I'm missing something. THanks.

---

<div class="post-metadata">

**Author:** ![Semyon](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@Semyon](https://discuss.elastic.co/u/Semyon)\
**Post date:** [February 23, 2018, 9:10pm UTC](https://discuss.elastic.co/t/logstash-output-to-es/121274/4 "2018-02-23T21:10:43Z")

</div>

Hi,

If you are using a hosted AWS ES service. be familiar with amazon cluster **access policy** double check networking between logstash instance and ES service, also create an AMI for this purpose of writing to ES.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [February 23, 2018, 9:53pm UTC](https://discuss.elastic.co/t/logstash-output-to-es/121274/5 "2018-02-23T21:53:03Z")

</div>

You already specify port 9243 in the hosts attribute, so you can remove it. You also don't need the protocol attribute. What you need to add is a username and password for your EC instance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2018, 9:54pm UTC](https://discuss.elastic.co/t/logstash-output-to-es/121274/6 "2018-03-23T21:54:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
